Impact
Drupal core includes a Server‑Side Request Forgery flaw that allows a remote actor to cause the server to send HTTP requests to arbitrary URLs. This vulnerability is identified as CWE‑918 and is disclosed in Drupal core versions from 0.0.0 up to 10.5.12, 10.6.0 to 10.6.11, 11.2.0 to 11.2.14, 11.3.0 to 11.3.12, all 11.0.x releases, and all 11.1.x releases.
Affected Systems
The affected product is Drupal core. Any installation running a core version within the ranges listed above is potentially vulnerable. Users should verify their installed version and consult the official advisory at https://www.drupal.org/sa-core-2026-008 for guidance.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, while the EPSS score of < 1% signals a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be remote via Drupal’s web interface, where an attacker supplies a crafted URL that the server resolves, initiating an outbound request.
OpenCVE Enrichment