it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
- Date: Wed, 17 Jun 2026 18:37:10 +0000
- Archived-at: <>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=BWeyt5wH; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=cTXCq+uk; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=4Uj393Yf; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.136 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org 932D16F49D
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp4.osuosl.org 5E451409BE
- Dmarc-filter: OpenDMARC Filter v1.4.2 smtp4.osuosl.org 5E451409BE
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-core-2026-009
Project: Drupal core [1]
Date: 2026-June-02
Security risk: *Moderately critical* 11 ∕ 25
AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Improper validation
Affected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 ||
>=11.3.0 <11.3.12 || 11.0.* || 11.1.*
CVE IDs: CVE-2026-55808
Description:
The JSON:API and REST modules allow you to upload image files to image
fields.
The validation rules check the file extension of the uploaded file but not
the file MIME type. This may allow a malicious user to upload a file that is
not an image.
Certain web-server configurations may serve the uploaded file with its actual
MIME type rather than an image type. This may lead to cross-site scripting
(XSS) or other unexpected behavior.
Solution:
Install the latest version:
*Drupal 11*
* If you use Drupal 11.3.x, update to Drupal 11.3.12 [3].
* If you use Drupal 11.2.x, update to Drupal 11.2.14 [4].
*Drupal 10*
* If you use Drupal 10.6.x, update to Drupal 10.6.11 [5].
* If you use Drupal 10.5.x, update to Drupal 10.5.12 [6].
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do
not receive security coverage. (Drupal 8 [7] and Drupal 9 [8] have both
reached end-of-life.)
Reported By:
* cantina_security [9]
Fixed By:
* Björn Brala (bbrala) [10]
* Kim Pepper (kim.pepper) [11]
* Lee Rowlands (larowlan) [12] of the Drupal Security Team
Coordinated By:
* Damien McKenna (damienmckenna) [13] of the Drupal Security Team
* Greg Knaddison (greggles) [14] of the Drupal Security Team
* Lee Rowlands (larowlan) [15] of the Drupal Security Team
* Dave Long (longwave) [16] of the Drupal Security Team
* Juraj Nemec (poker10) [17] of the Drupal Security Team
* Jess (xjm) [18] of the Drupal Security Team
Security
issue:
https://git.drupalcode.org/security/185032-drupal-security/-/work_items/1
[19]
------------------------------------------------------------------------------
Contribution record [20]
[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/drupal/releases/11.3.12
[4] https://www.drupal.org/project/drupal/releases/11.2.14
[5] https://www.drupal.org/project/drupal/releases/10.6.11
[6] https://www.drupal.org/project/drupal/releases/10.5.12
[7] https://www.drupal.org/psa-2021-06-29
[8] https://www.drupal.org/psa-2023-11-01
[9] https://www.drupal.org/u/cantina_security
[10] https://www.drupal.org/u/bbrala
[11] https://www.drupal.org/u/kimpepper
[12] https://www.drupal.org/u/larowlan
[13] https://www.drupal.org/u/damienmckenna
[14] https://www.drupal.org/u/greggles
[15] https://www.drupal.org/u/larowlan
[16] https://www.drupal.org/u/longwave
[17] https://www.drupal.org/u/poker10
[18] https://www.drupal.org/u/xjm
[19] https://git.drupalcode.org/security/185032-drupal-security/-/work_items/1
[20] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3593385
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009, security-news, 17.06.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.