it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
- Date: Wed, 15 Jul 2026 19:49:34 +0000
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/6UARXKWAA62REOHEILVBEODFH4YN6YQJ/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="I6/+091L"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=Lzp6EN48; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Ime8dkU8; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp1.osuosl.org 9814C8136B
- Dkim-filter: OpenDKIM Filter v2.11.0 smtp3.osuosl.org D9B84605E7
- Dmarc-filter: OpenDMARC Filter v1.4.2 smtp3.osuosl.org D9B84605E7
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-core-2026-010
Project: Drupal core [1]
Date: 2026-July-15
Security risk: *Moderately critical* 10 ∕ 25
AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:Uncommon [2]
Vulnerability: Information disclosure
Affected versions: <10.6.13 || >=11.3.0 <11.3.14 || >=11.4.0 <11.4.4 ||
11.0.* || 11.1.* || 11.2.*
CVE IDs: CVE-2026-15916
Description:
The Image module allows you to define and configure image fields.
The module doesn't sufficiently check access to image style derivatives when
those files are served via a file stream other than private://.
This vulnerability is mitigated by the fact that Drupal must be configured to
use a contributed (non-core) file scheme to serve private derived images.
Information disclosure issues like this one are not generally given security
advisories (as described in PSA-2023-07-12) [3]). This fix is provided as a
hardening. Contributed modules implementing custom stream wrappers may need
to add similar hardenings.
Solution:
Install the latest version:
*Drupal 11*
* If you use Drupal 11.4.x, update to Drupal 11.4.4 [4].
* If you use Drupal 11.3.x, update to Drupal 11.3.14 [5].
* Drupal 11.2.x and below are end-of-life and do not receive security
coverage.
*Drupal 10*
* If you use Drupal 10.6.x, update to Drupal 10.6.13 [6].
* Drupal 10.5.x and below are end-of-life and do not receive security
coverage.
Drupal 8 [7] and Drupal 9 [8] have both reached end-of-life.
Reported By:
* offensive-ai [9]
Fixed By:
* Benji Fisher (benjifisher) [10] of the Drupal Security Team
* Kim Pepper (kim.pepper) [11]
* Mohit Aghera (mohit_aghera) [12]
Coordinated By:
* Benji Fisher (benjifisher) [13] of the Drupal Security Team
* catch (catch) [14] of the Drupal Security Team
* Lee Rowlands (larowlan) [15] of the Drupal Security Team
* Juraj Nemec (poker10) [16] of the Drupal Security Team
* Jess (xjm) [17] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [18]
[1] https://www.drupal.org/project/drupal
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/psa-2023-07-12
[4] https://www.drupal.org/project/drupal/releases/11.4.4
[5] https://www.drupal.org/project/drupal/releases/11.3.14
[6] https://www.drupal.org/project/drupal/releases/10.6.13
[7] https://www.drupal.org/psa-2021-06-29
[8] https://www.drupal.org/psa-2023-11-01
[9] https://www.drupal.org/u/offensive-ai
[10] https://www.drupal.org/u/benjifisher
[11] https://www.drupal.org/u/kimpepper
[12] https://www.drupal.org/u/mohit_aghera
[13] https://www.drupal.org/u/benjifisher
[14] https://www.drupal.org/u/catch
[15] https://www.drupal.org/u/larowlan
[16] https://www.drupal.org/u/poker10
[17] https://www.drupal.org/u/xjm
[18] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3609660
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010, security-news, 15.07.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.