Drupal uses JavaScript to render status messages in some cases and configurations. In certain situations, the status messages are not adequately sanitized.
Install the latest version:
If you are using Drupal 10.2, update to Drupal 10.2.11.
If you are using Drupal 10.3, update to Drupal 10.3.9.
If you are using Drupal 11.0, update to Drupal 11.0.8.
All versions of Drupal 10 prior to 10.2 are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
catch of the Drupal Security Team
Mingsong
Juraj Nemec of the Drupal Security Team
Dave Long of the Drupal Security Team
Benji Fisher of the Drupal Security Team
More Stories
USN-7340-1: OpenVPN vulnerabilities
It was discovered that OpenVPN did not perform proper input validation when generating a TLS key under certain configuration, which...
USN-7338-1: CRaC JDK 17 vulnerabilities
Andy Boothe discovered that the Networking component of CRaC JDK 17 did not properly handle access under certain circumstances. An...
USN-7339-1: CRaC JDK 21 vulnerabilities
Andy Boothe discovered that the Networking component of CRaC JDK 21 did not properly handle access under certain circumstances. An...
USN-7337-1: LibreOffice vulnerability
It was discovered that LibreOffice incorrectly handled Office URI Schemes. If a user or automated system were tricked into opening...
USN-7299-2: X.Org X Server vulnerabilities
USN-7299-1 fixed several vulnerabilities in X.Org. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS....
thunderbird-128.8.0-1.fc41
FEDORA-2025-bd6664e83b Packages in this update: thunderbird-128.8.0-1.fc41 Update description: Update to 128.8.0 https://www.mozilla.org/en-US/security/advisories/mfsa2025-18/ https://www.thunderbird.net/en-US/thunderbird/128.8.0esr/releasenotes/ Read More