Drupal core’s form API has a vulnerability where certain contributed or custom modules’ forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.6.
If you are using Drupal 9.2, update to Drupal 9.2.13.
If you are using Drupal 7, update to Drupal 7.88.
All versions of Drupal 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Lee Rowlands of the Drupal Security Team
Ben Dougherty of the Drupal Security Team
Drew Webber of the Drupal Security Team
Jen Lampton
Nate Lampton
Fabian Franz
Alex Bronstein of the Drupal Security Team
More Stories
libxml2-2.12.10-1.fc40
FEDORA-2025-adbb0031f7 Packages in this update: libxml2-2.12.10-1.fc40 Update description: Update to 2.12.10 Read More
libxml2-2.12.10-1.fc41
FEDORA-2025-65790c11eb Packages in this update: libxml2-2.12.10-1.fc41 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
libxml2-2.12.10-1.fc42
FEDORA-2025-b9170cd464 Packages in this update: libxml2-2.12.10-1.fc42 Update description: Update to 2.12.10 Fix CVE-2024-56171 and CVE-2025-24928. Read More
kitty-0.40.0-2.fc40
FEDORA-2025-2fe21e3da5 Packages in this update: kitty-0.40.0-2.fc40 Update description: Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes Read More
USN-7351-1: RESTEasy vulnerabilities
Nikos Papadopoulos discovered that RESTEasy improperly handled URL encoding when certain errors occur. An attacker could possibly use this issue...
USN-7344-2: Linux kernel vulnerabilities
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could...