Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
  • Date: Wed, 23 Sep 2026 16:46:53 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=amj+kHdq; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Z13+ndIL; arc=none smtp.remote-ip=54.240.27.115
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 5137F40F6F
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org CC09C40282
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185771; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=LuXnmhC1xJvsQ0OWb9SA0soQt/nW3H75Y4DBS8VQ4NA=; b=U3lFNPBZjHyNl8IJOKaV5x5UNqGybk1GDxZGv0rj32cXUQasc/DfOfHLNk/QVWZANAWZ KNmgQOg7mkjrJfL9z5KoX+dWQfQQ64RBzFS7BH8QawAaaLHBOZ+2ZLSo21C+zBkV5J8fC 3LMpd92aSageLOSEqQN0H3kGNuCDyLd5N4KzAZt+1tK6+EwtWmCDBOF6ncaYa3sDyVNk9 zj54oACJ3rVd/Ur/8lry5fMj/Zz8RE2WcFeGd7Mf0dnaqFp5VsVdmsCwEmcSpOAeuPD9H v/FPLVD3GaCzF4h0eZpkaOSoCQX5yHiLo9UskCxBUayZXAPaaxMUy481QrrVqBZT+zg==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182014; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=uI0LCxLninRAB4oXuJrKgUG8aEqK07voNRHeHYd2JVc=; b=RiKjnIiA29dqiWHxz//ca6SQdOmJNu3L7GOcl7KByhw2HLC0dQcn6hgV2zwkreDCKjUW BaGmcNub755TNwtaMCoNu+yn8pMh3AYOqfBWhTN7NwwYMNakc6XzI/QmfbPJRRbCtMw40 r23X5WSGxa1Sz+mYL3NwH8iqCH6o/X1rvos8VQs19h5Fw0iqzt4Pu3f0JUNdEQPVdR1af OQCfiZ1rWip3jv3H52Up385GTKVgdU5dkge0hs8OnZ/xMOffWFirduQSo+iYSMTnHncLz xk1SwvP3MicwEY/ym8hgoR4U5JXyvYXn0Iwy4m8ywJ+pFZ+j+46BhRTH63W7zR4629g==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185771; b=fXhpbn5sEMqZXSK2rLP4GMJXN8+wIOy6rXac8W6Vxk/4ClCU4lGs2q74NEClLSyhW38U WTkhM4RjVEcJ+60iB9u5+XJqDbUo4HdYgqmL7bAdSo9wpvtKHpNDMXWEf2PipuRyzyNAW vBEhmXYCiicQG8dr+cnQD4Mh3MkWFeZQ1iOhRcnuhoXQOuFeRoVP19HzrgE3T0QPbQSy9 lyjRA+bw9FiGvpnFfJleBXE//SGMihcTeAurpPfOPXyd3OZU0NfU3/BSRmEj/q9FCIWWp 78LuQ0s3wG+WXkHXphyAP4B5Uu5U4PcYI2L9f0lQ9ZFRjGk4TLMYPShmBVqZSOQL+ig==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182014; b=d8ZfE02GyshbKkuZAlNlKU2mJ+uL+o4jyuMjq/O2SisPnR7mOWw0g7s3oYZQSN8SS2ae BLZ87g4a46h45SFVFECQtfp1WLK1KQD5GDXaRecweD/nsiT76QSOVMWl0DznB+9Qe9P3d W69JJXoV7WhgjB+XDnBf/KMiQ5M0XHgKQNp0J/x96qMiZAIl3obEu3hqu1FpKQ+ng0YjM HnPXUT5XcjcYts4vVHh0eBrbMFmntOZUu3Mf+SRxGF+PaV30oGtiInAEVlY9daYyVxZzz P8Zrd1cYMbjaXTq8kK3LoK4pB3Hy7cIwi/MKTQA+K8KSxijn2LMuTZfchBF6JZomh4Q==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/CBRZRTEKCLY2MKJHR2B6DY2SKMBWVFNH/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=e9ZCo6NY; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=amj+kHdq; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=Z13+ndIL; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-160

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross-site scripting

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96362
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data. Site builders may also
configure handlers for processing submissions. Remote Post Handlers send
webform data to other servers via APIs.

The module does not sufficiently filter response values from the Remote Post
handler before those values are rendered through handler response tokens. If
a site uses Remote Post handler response tokens in rendered output, values
returned by a configured remote endpoint could be rendered as HTML, resulting
in a cross-site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must be able to
control or influence the response from a configured remote endpoint, and the
site must use Remote Post handler response tokens in rendered output.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Brian Willows (hsjbrianwillows) [5]

Fixed By: 
* Jacob Rockowitz (jrockowitz) [6]
* Lee Rowlands (larowlan) [7] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* cilefen (cilefen) [10] of the Drupal Security Team
* Greg Knaddison (greggles) [11] of the Drupal Security Team
* Juraj Nemec (poker10) [12] of the Drupal Security Team
* Jess (xjm) [13] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [14]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/hsjbrianwillows
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/larowlan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/cilefen
[11] https://www.drupal.org/u/greggles
[12] https://www.drupal.org/u/poker10
[13] https://www.drupal.org/u/xjm
[14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3601420

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang