Server-side Request Forgery (SSRF) Affecting drupal/core package, versions <10.5.12>=10.6.0, <10.6.11>=11.0.0, <11.2.14>=11.3.0, <11.3.12


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-DRUPALCORE-17950581
  • published11 Jul 2026
  • disclosed11 Jul 2026
  • creditUnknown

Introduced: 11 Jul 2026

NewCVE-2026-55807  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade drupal/core to version 10.5.12, 10.6.11, 11.2.14, 11.3.12 or higher.

Overview

drupal/core is an an open source content management platform powering millions of websites and applications.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the request process. An attacker can make arbitrary requests to internal or external systems by supplying crafted URLs.

CVSS Base Scores

version 4.0
version 3.1