Drupal core’s form API has a vulnerability where certain contributed or custom modules’ forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
This advisory is not covered by Drupal Steward.
Install the latest version:
If you are using Drupal 9.3, update to Drupal 9.3.6.
If you are using Drupal 9.2, update to Drupal 9.2.13.
If you are using Drupal 7, update to Drupal 7.88.
All versions of Drupal 9 prior to 9.2.x are end-of-life and do not receive security coverage. Note that Drupal 8 has reached its end of life.
Lee Rowlands of the Drupal Security Team
Ben Dougherty of the Drupal Security Team
Drew Webber of the Drupal Security Team
Jen Lampton
Nate Lampton
Fabian Franz
Alex Bronstein of the Drupal Security Team
More Stories
dotnet8.0-8.0.114-1.fc40
FEDORA-2025-83c147615e Packages in this update: dotnet8.0-8.0.114-1.fc40 Update description: This is the monthly update for .NET for March 2025. Release Notes:...
dotnet8.0-8.0.114-1.fc41
FEDORA-2025-adbd75f500 Packages in this update: dotnet8.0-8.0.114-1.fc41 Update description: This is the monthly update for .NET for March 2025. Release Notes:...
dotnet8.0-8.0.114-1.fc42
FEDORA-2025-54ac622cef Packages in this update: dotnet8.0-8.0.114-1.fc42 Update description: This is the monthly update for .NET for March 2025. Release Notes:...
USN-7328-3: Linux kernel vulnerabilities
Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker...
expat-2.7.0-1.fc40
FEDORA-2025-d487e15b69 Packages in this update: expat-2.7.0-1.fc40 Update description: Rebase to 2.7.0 Read More
expat-2.7.0-1.fc41
FEDORA-2025-20e86a3c86 Packages in this update: expat-2.7.0-1.fc41 Update description: Rebase to 2.7.0 Read More