Early access: the directory is still filling out, and every rating here is a reported experience.

Security releases

Drupal

Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

SA-CORE-2026-008 Jun 17, 2026 Source: Vendor

Imported by the Drupal advisory catcher from https://www.drupal.org/sa-core-2026-008. 13 reporter(s), 5 fixer(s). Draft. Review before publishing.

Source of record The credited names below are quoted verbatim from the vendor's own advisory: https://www.drupal.org/sa-core-2026-008
Are you credited here? Sign in and claim your line: it is yours immediately, no review queue. The name the vendor printed stays next to your handle for anyone to check against the advisory above, and any member who thinks a claim is wrong can refute it.

Credited

18 lines
Showing 1–18 of 18
CVE-2026-55807 BR2026-0000-007337 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Hamed Kohi (0xhamy)
CVE-2026-55807 BR2026-0000-007338 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as assaf alassaf (ama62)
CVE-2026-55807 BR2026-0000-007339 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Albert Skibinski (askibinski)
CVE-2026-55807 BR2026-0000-007340 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Jon Minder (ayalon)
CVE-2026-55807 BR2026-0000-007341 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Lautaro Casanova (betah4k)
CVE-2026-55807 BR2026-0000-007342 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Gabe Sullice (gabesullice)
CVE-2026-55807 BR2026-0000-007343 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as John Morahan (john morahan)
CVE-2026-55807 BR2026-0000-007344 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Michael Winser (michaelwinser)
CVE-2026-55807 BR2026-0000-007345 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as nbanderson
CVE-2026-55807 BR2026-0000-007346 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as offensive-ai
CVE-2026-55807 BR2026-0000-007347 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Francesco Placella (plach)
CVE-2026-55807 BR2026-0000-007348 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as quynh ho (qquynh)
CVE-2026-55807 BR2026-0000-007349 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Himanshu Anand (unknownhad)
CVE-2026-55807 BR2026-0000-007350 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Lee Rowlands (larowlan) of the Drupal Security Team
CVE-2026-55807 BR2026-0000-007351 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Dave Long (longwave) of the Drupal Security Team
CVE-2026-55807 BR2026-0000-007352 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Drew Webber (mcdruid) of the Drupal Security Team
CVE-2026-55807 BR2026-0000-007353 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Adam G-H (phenaproxima)
CVE-2026-55807 BR2026-0000-007354 unclaimed
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Credited as Sean Blommaert (seanb)