Four Moderately Critical Vulnerabilities Patched in Drupal Core

Four Moderately Critical Vulnerabilities Patched in Drupal Core

Drupal has released four security advisories addressing moderately critical vulnerabilities across all supported core versions, urging immediate updates to avoid potential Denial of Service, gadget chain exploitation, defacement, and information disclosure risks.

One advisory (SA-CORE-2025-005) addresses a Denial of Service risk where a rarely used feature, tied to an underlying HTTP library, can override certain request attributes. This can poison cache entries and lead to malformed or incorrect page rendering. Drupal core has been updated to harden against this issue while upstream changes are pending.

Another issue (SA-CORE-2025-006) involves a gadget chain that is not directly exploitable but could allow remote code execution if another insecure deserialization vulnerability is present. While no such exploits exist in Drupal core currently, the chain has been mitigated preemptively.

A third vulnerability (SA-CORE-2025-007) enables temporary site defacement via specially crafted URLs. These URLs cause transient alterations to site appearance, but the defacement is not persistent and does not expose underlying content.

The final advisory (SA-CORE-2025-008) describes an information disclosure scenario involving cached private files. If custom or contributed modules define additional file schemes, and these files are accessed by privileged users and then cached, subsequent access by others may reveal data they should not see. This issue is configuration-dependent and has been addressed in the patch.

All four issues affect Drupal core versions from 8.0.0 through recent 11.2.x releases. Recommended updates include versions 10.4.9, 10.5.6, 11.1.9, and 11.2.8. Older branches, including 10.3.x and 11.0.x, are end-of-life and not covered by these security releases.

All advisories are classified as “Moderately Critical” by the Drupal Security Team. Administrators should assess their site’s core version and update immediately to mitigate the outlined vulnerabilities and reduce exposure to indirect attack vectors such as gadget chains or caching misconfigurations.

Administrators should update their Drupal core installations to the latest supported versions. Visit the official Drupal Security advisories page for full patch notes and guidance.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities