Drupal core’s form API has a vulnerability where certain contributed or custom modules’ forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.6.
If you are using Drupal 9.2, update to Drupal 9.2.13.
If you are using Drupal 7, update to Drupal 7.88.
All versions of Drupal 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Lee Rowlands of the Drupal Security Team
Ben Dougherty of the Drupal Security Team
Drew Webber of the Drupal Security Team
Jen Lampton
Nate Lampton
Fabian Franz
Alex Bronstein of the Drupal Security Team
More Stories
nextcloud-29.0.16-1.el9
FEDORA-EPEL-2025-9129f1f736 Packages in this update: nextcloud-29.0.16-1.el9 Update description: 29.0.16 release RHBZ#2345763 Read More
chromium-135.0.7049.95-1.fc42
FEDORA-2025-fb323a2b22 Packages in this update: chromium-135.0.7049.95-1.fc42 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc40
FEDORA-2025-7827e4feac Packages in this update: chromium-135.0.7049.95-1.fc40 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el10_1
FEDORA-EPEL-2025-af0c337351 Packages in this update: chromium-135.0.7049.95-1.el10_1 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el9
FEDORA-EPEL-2025-5104c5b9be Packages in this update: chromium-135.0.7049.95-1.el9 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc41
FEDORA-2025-9c1d536035 Packages in this update: chromium-135.0.7049.95-1.fc41 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...