| ID | PPSA-202605-1 |
|---|---|
| Published | 2026-05-08 |
| Private Packagist Cloud | Affected. Fixed on 2026-05-08. |
| Private Packagist Self-Hosted (KOTS) | Affected < 2.0.33. Fixed in 2.0.33. |
| Private Packagist Self-Hosted (Helm) | Affected < 2.0.33. Fixed in 2.0.33. |
Summary
Signatures of requests to the Private Packagist REST API did not cover the URL query parameters.
Who was affected
Users of the REST API with signed requests, on Private Packagist Cloud until the fix on May 8, 2026, and on Private Packagist Self-Hosted installations running a version before 2.0.33.
Impact
An attacker able to intercept and modify the encrypted traffic between an API client and Private Packagist, for example through a TLS-intercepting proxy under their control, could have changed the query parameters of a signed request without Private Packagist rejecting it. Only endpoints that list data use query parameters, for pagination and for filtering security issues by state. The attacker could therefore have made a client receive a different part of a list than it requested, for example an incomplete list of packages, or security issues in a different state than requested, which could mislead automation that relies on these results. They could not change request bodies, call other endpoints, repeat requests, or access data beyond what the client's API credentials allow.
What we did
We introduced version 2 of the request signature, which also covers the query parameters. The previous signature version is deprecated and support for it will eventually be removed.
Do customers need to do anything
- Everyone using the REST API: Upgrade private-packagist/api-client to version 1.41.0 or later, which uses the new signature:
composer require private-packagist/api-client:^1.41If you sign requests with your own code, switch to the version 2 signature described in the API authentication documentation.
- Private Packagist Self-Hosted: Upgrade to 2.0.33 or any later version. We recommend upgrading to the latest release.
Credits
Thanks to Aditya Singh for reporting this issue.
Start Free Trial
Login to create an organization and start your free trial!