CVE-2026-11914: Composer - Critical - Unsupported - SA-CONTRIB-2026-046
Published Jul 10, 2026
·Updated
vulnerability in Drupal Composer allows . This issue affects Composer versions: ..
Affected Software
1 affected component
Composer=*.*.
Event History
Jul 10, 2026
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
Description
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-11914?
CVE-2026-11914 has a medium severity rating with a CVSS score of 5.9.
2
How do I fix CVE-2026-11914?
To mitigate CVE-2026-11914, update to a patched version of Composer that addresses the vulnerability.
3
What types of systems are affected by CVE-2026-11914?
CVE-2026-11914 affects all versions of Composer that are in use.
4
What is the nature of the vulnerability in CVE-2026-11914?
CVE-2026-11914 is an input validation vulnerability found in the Drupal Composer.
5
When was CVE-2026-11914 published?
CVE-2026-11914 was published on July 10, 2026.