Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
  • Date: Wed, 23 Sep 2026 16:47:08 +0000
  • Arc-authentication-results: i=2; smtp4.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Qjc9gcnR; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=s2lwAUbo; arc=none smtp.remote-ip=54.240.27.34
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 175584A4D4
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org E1C9940282
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790185988; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=7z6KGKZf/qeFdxXl3wJo3blckctq2zWCBkmDoK2selg=; b=p1XceVtMUeANVdqKD3BgVQL1LrLH38wU0cW/G6Ectu0aKOUyMXgqEd2d7AKmwYEQjqaF Yfq6obB/9dvqgqaLd6Cz0m1H+spHTDds/ypkuwuLtYckAilC/rx6EvzsOU4N53Q4fsKID Dx6eK2v6mYF3QCLgZqyoocENbL7fti1HUFR4dpS0JRgna3QahOenu2PnLsrrkwAXrN50A 5ougT6TeM1YeCPAnG0suzOd/UiigwdskRNBGtA5zlVnxdKNOLOzH+HIj999XRtJ6R5FlT fMFlTnbS7Txz+qpOF77RUsFoIkoy+BZyWDavQQWGVBm7xlqiJvkvvSMMSxA9G1uNjQQ==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182029; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=oNXia00gMorWHKnxw/jCXz7JzJZEbG83v0AAfN5+Du0=; b=Ow/WEguHUZhu2CfFuowd0v1+UPOrtDhp+ci3AdTvaTXamEPR9Cl4BTXXe7MNqi76jb5f qcnO/WB5KtlmRikE2N+LZO53u5tVBz7DozQ0GDZ4QhQzhF/55q+Hmk7YrjVZU8cN7H2Eb vbsK80Bqjd+Dgzc1XAkIOCkofPdgC3KYA2biupUvSujVupW6VwUNJM3gC9f/8KqoIySTc x1QjRterdNnDEdHWVtoEY1xbVYvaSLPwLLmtIp6wlLlwP8XhHzotVcH4Oyvuvt2egwqsU GTXCCxnDLOWB+nk83RQ9d/8UccPEA9QBD7WSdUfe5OnJ0pUoIPx/R/ci6NDMvRlea6w==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790185988; b=JWmJ/Nk1RvRVaIgWZTwTLb4TqNT2WQlfZpmAXTGUnTZN9zbJZrQZEzGs8Ot9z9MLPoPD BI1srqfl5qn1LTbJqSfPu9d3rJ6n1M8z8YNur6v37CFCn4MQv04BQlwKRohSaLW3ZkD6g YSsJCt9RuxUKmUwE3eIz5asurJlv/vjD/moiEecMC9PlVuePwdtsD+yBOZ0bYAVKLI/sq QoGKyD9D6ewRd025XAYifwyAY/cXiG3UwbrQWqg7KyDSvNhfiLJpQPRVRn5jZ9EQ6XoD7 LdpVG0YcKl65nN8e/XOuAceU40WTj8gjh11a65GNSYxe9CO5HAl8Ega4mX5Lx0K6vDw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182029; b=dXRpHvfy5dCI4Xc3ibqPH0Igm31Z/mXlF49vhbY5wEH0xcPpGIFBSSsj0/c5SA0bY4LH Brmr3oeATDYAYhcswanhcAep4BEpuqwpo2TgabUVAy8elesqPbjGSwaVU/lTROLES28V6 hH2NbpCHiGJAE6A9pmkgAJ0XnpBMSr3/mSN6fqYovlOHOW8j2wNVvQE7B5SyTSfTQBevp KdYv5ZsUU+3ROveh67H3PGctf/iIwmwNRg+ZmgGG9ReyVc3TY4BKRUoJhoWWkv8OFMTvF IWIso7r1ssZ5sV58ScaKJaL1G03R8iQwDtkXOk8eo7QiWSUtF7HAiDrBqC8OiBP5peg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/OSX7HDANVDD5UDLEZMSEYGFHKSOWD3KF/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=B1mt9Lqv; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=Qjc9gcnR; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=s2lwAUbo; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-159

Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross-site scripting

Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96359
Description: 
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data.

The module did not sufficiently sanitize attributes used by its color
element. Under certain conditions, specially crafted attributes could result
in cross-site scripting (XSS) when the element is rendered.

This vulnerability is mitigated by the fact that an attacker must be able to
add a specially crafted link with a specific class to the same page as the
affected webform.

Solution: 
Install the latest version:

* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].

Reported By: 
* Pierre Rudloff (prudloff) [5] of the Drupal Security Team

Fixed By: 
* Jacob Rockowitz (jrockowitz) [6]
* Lee Rowlands (larowlan) [7] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Pierre Rudloff (prudloff) [11] of the Drupal Security Team
* Jess (xjm) [12] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [13]

[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/prudloff
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/larowlan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/prudloff
[12] https://www.drupal.org/u/xjm
[13] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3600594

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang