Description
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Published: 2026-07-10
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Drupal core includes a Server‑Side Request Forgery flaw that allows a remote actor to cause the server to send HTTP requests to arbitrary URLs. This vulnerability is identified as CWE‑918 and is disclosed in Drupal core versions from 0.0.0 up to 10.5.12, 10.6.0 to 10.6.11, 11.2.0 to 11.2.14, 11.3.0 to 11.3.12, all 11.0.x releases, and all 11.1.x releases.

Affected Systems

The affected product is Drupal core. Any installation running a core version within the ranges listed above is potentially vulnerable. Users should verify their installed version and consult the official advisory at https://www.drupal.org/sa-core-2026-008 for guidance.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, while the EPSS score of < 1% signals a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is inferred to be remote via Drupal’s web interface, where an attacker supplies a crafted URL that the server resolves, initiating an outbound request.

Generated by OpenCVE AI on July 31, 2026 at 12:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Drupal core to the latest release that includes the SSRF fix, ensuring the installed version is newer than the affected ranges listed in the advisory.
  • If an upgrade is not immediately possible, restrict Drupal’s outbound network access by configuring firewall rules or network segmentation to block unintended HTTP/HTTPS calls to internal or sensitive services.
  • Audit custom modules and user‑supplied inputs that may trigger outbound requests, and monitor application logs for anomalous outgoing traffic.

Generated by OpenCVE AI on July 31, 2026 at 12:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal drupal Core
Vendors & Products Drupal
Drupal drupal Core

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Title Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Weaknesses CWE-918
References

Subscriptions

Drupal Drupal Core
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:20:30.331Z

Reserved: 2026-06-17T14:59:52.673Z

Link: CVE-2026-55807

cve-icon Vulnrichment

Updated: 2026-07-13T18:20:26.051Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)