Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105
  • Date: Wed, 26 Aug 2026 17:34:36 +0000
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/WMMS22FTAQVYTXOSXJ3GJXGWKUVF3RG6/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="Z/HB1cCw"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=f34odw3mfzgsrgyn3evjayysxxl6jizn header.b=aqdn0rL2; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=r9OqBe5D; dmarc=pass (policy=none) header.from=drupal.org; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.138 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-105

Project: CAPTCHA Protected Page [1]
Date: 2026-August-26
Security risk: *Moderately critical* 12 ∕ 25
AC:Complex/A:None/CI:Some/II:None/E:Theoretical/TD:All [2]
Vulnerability: Cookie Forgery

Affected versions: <1.0.2
CVE IDs: CVE-2026-81168
Description: 
This module enables site administrators to require CAPTCHA confirmation on
specific pages.

The module does not sufficiently validate its CAPTCHA verification cookies.
Under certain circumstances, an unauthenticated user or automated bot can
forge the cookie and bypass CAPTCHA verification entirely.

Solution: 
Install the latest version:

* If you use the CAPTCHA Protected Page module, upgrade to CAPTCHA Protected
Page 1.0.2 [3].

Reported By: 
* lovasoa [4]

Fixed By: 
* Carlo Miguel Agno (carlagno) [5]
* Mark Jayson Gruta (mjgruta) [6]

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Carlo Miguel Agno (carlagno) [8]
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Heine Deelstra (heine) [10] of the Drupal Security Team
* Juraj Nemec (poker10) [11] of the Drupal Security Team
* Jess (xjm) [12] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [13]

[1] https://www.drupal.org/project/captcha_protected_page
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/captcha_protected_page/releases/1.0.2
[4] https://www.drupal.org/u/lovasoa
[5] https://www.drupal.org/u/carlagno
[6] https://www.drupal.org/u/mjgruta
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/carlagno
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/heine
[11] https://www.drupal.org/u/poker10
[12] https://www.drupal.org/u/xjm
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3612587

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105, security-news, 26.08.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang