it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
- Date: Wed, 23 Sep 2026 16:46:18 +0000
- Arc-authentication-results: i=2; smtp4.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=D1u3Q9K7; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Ut5xOCUA; arc=none smtp.remote-ip=54.240.27.38
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 3291C41417
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 092F040282
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185300; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=DAgcj3ZPDPnN63Sys9+nrNz6X85UN2XXTXpMrEjzRKQ=; b=Xy3FwAyO+/ZAQKhDhvN4GJJ4txVBe2igXG/U5sWX7juf8neXIhJMY/fIpeKqXndgpDGW flKflV38MPDOXgj9T33/AP+pO69QHlxkJ2rpQ2IcW89x5Kg7P/VIqSmwD0bXzcqio07Gj teZqWJ7wW+qq03REt5pKB985/Sw7EwjX2prMnA6mrkfKZQSTr6kY3Ezn9iddQpmPksTFd tR+X7EFSHu8yc+D20+I0xYhUQISMveSjLBlsoSgBKEUeh/+vD8DW16AtSHj91AQf65MBg PmmdeHf9J+MaYwhOMyWqFj3h9vOgYhloaJwABvIs2cwyTLdtNby3Nkyk5snDH1jyISQ==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790181981; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=GeNGkaLFhKA+K+GSLyytumvjaX3dnkxJtEPy20TkqXE=; b=HKgEBjLPSYbziRdGUmFYLE7Og9zzZgbsERVdbaYnUKQ1QJ7OjC8SVuBF82pbHLmlJa62 fqTb91o5R2+EH5RyN/eGc4zy9pfGqCyXRRrebNOnMQPeCgAbPvnmgO1po1uxBlV3hE8xP ah1cW2x1HHatxNYhuZ0eD7FH/LQU+pqYVukvgJESN4GgJZB6q8MyroetupDA8aTdT/atE 9D4pw8hNkScZAN681dH2bv1U0wnY7VKvyps5JmOd1ZHtOVFshazptQQ4zT2CfTrgobmyI kD47Megdj4QoEGNzxpkXvf+w/Q32xc+rmDmW4BoTKbA88x7R36oHsPThJuGhUL/6mkg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185300; b=kNaA/yFpaVuHdf8R8Zp5lyzYjIIOKVEY/WQto5zhJHFP8AKi+PoWKvURi8D5J9Q1EDqO 3Z+q/Ka+RuTYz6Wb+gFrlYdjykNTWsDgTipop4fX5GYWNTZ3b9/obeuNpvcJoZwAwcM8h DIYY8bII5M3NMnFR9RvpRHr+KOzR2E+EdqOft6ONEVTU/0kMFACT/Q6zXzXuBWdn6Te8p 48QhlVfM+4YU731tIiRR8TJ8J/7w72vsu8p/G3svlnLc1ePwZ6sKm7lq9MNYl8pIsyMoM QDXWALUpL5pbXYkbx+CssVaeUEEZpUn+HrSe6A5WeozdmZ7VZMKF8AXDLBLM8Er0RvQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790181981; b=WkVdaB2FqQM3xcGWWwt6oKxaNe8P1IYwZnYBzbp4Rs+6fe/yexQDix0qVC9lLohhSRiJ xQ4eUHsBGzd+3UDNHoUaSYJXsdOQWSHCfCEYah9iyxJpIoyjTL0jLh8TTxU1IW3Tqg1gU rDZuCYgKHSKoSBWUSiNtTwB2yFq8QQQ3o/rSxDmeS1bRyfLp2okK7tqEkks+RyGw4hSku 1UdrJrQC+wq0XSuR06LodHFv4ZiQaeJ6Mxq+PXUWAdh+XGRXDu0IHvBZtZ6WdWKqPiBH7 eMnrJHyXm/feTD7PZ+BDuXITALzUX+MK+nokrlyh3spvTZ8gOC0Y86SDD6MErw+fIBg==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/I6ACXA4K4AXPJPK4YYH4ZSBR7FPEFQVK/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=HfWcydMC; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=D1u3Q9K7; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Ut5xOCUA; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-163
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross-site scripting
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96368
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data. Site builders may add
tooltips and help text to these forms.
Some Webform tooltips and help text were not sufficiently sanitized,
resulting in possible cross-site scripting (XSS).
This vulnerability is mitigated by the fact that an attacker must have
permission to create or edit affected Webform configuration or content.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Pierre Rudloff (prudloff) [5] of the Drupal Security Team
Fixed By:
* Jacob Rockowitz (jrockowitz) [6]
* Lee Rowlands (larowlan) [7] of the Drupal Security Team
Coordinated By:
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Neil Drumm (drumm) [10] of the Drupal Security Team
* Pierre Rudloff (prudloff) [11] of the Drupal Security Team
* Jess (xjm) [12] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [13]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/prudloff
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/larowlan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/drumm
[11] https://www.drupal.org/u/prudloff
[12] https://www.drupal.org/u/xjm
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3611222
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.