{"id":"CGA-qc9g-m2cj-3pm6","modified":"2026-07-17T20:12:58.451209715Z","published":"2026-04-24T13:15:13.578272Z","withdrawn":"2026-07-17T20:12:58.451209575Z","related":["CVE-2026-40261","GHSA-gqw4-4w2p-838q"],"affected":[{"package":{"name":"composer","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.7-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-qc9g-m2cj-3pm6.json"}},{"package":{"name":"composer","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/composer"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.7-r0"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-qc9g-m2cj-3pm6.json"}}],"schema_version":"1.7.5"}