it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
- Date: Wed, 23 Sep 2026 16:47:18 +0000
- Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=eH1TVhFJ; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=2QampLXj; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=eH1TVhFJ; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=2QampLXj; arc=none smtp.remote-ip=54.240.27.38
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 4A0F541675
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 97F1340568
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186151; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=vZCblQhSASuSysjzgg1XU6PKCE1KE9jaXY0TZ5oH0Ww=; b=Hp+SDejAm+gi1rGEwg4u7yh7nSRrruemRtXy4/V33MnLMAOXnx5soaZcy1K3QT7+JL/N OewW1W/MHXwCRNxH7w0bKzLn9p5r0yVlriY6wPWrw4dUtp/KLkBizPu/vUTr3QKBlXd7x BLh0TKTD9B/wbM5nC5tkhroulAyV1Zpep4PdMeo8ZFv1hS6d1UCer/a8dju5sFiPzedRw p/MfkjryUTDBZuXyjnYMB+NOX21VB+A/MajsPhiLnV5ys/alfr3Dc4oRbcCywu6as+PZl UoTvWpDxKoZWj4mdIrN/wu+MQe2aQVEByTVcSyAcdH7cor7olm443R8/AbERjmzaE1A==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182039; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=r38yJyQMT1sKc+YhUCzAy6bfF7Ma1w0smT9+qqLGwTE=; b=oBpc1Zm5Ku2BHcrd7TWW8k4cfXTwI7UtT6ztvUsg2RrzBML9qFf0Y2Hy2XAUKSasz9sN 52fuh0yssXGL2b4j0BOwL+mQACoQrzOd3Pm4tATKu99b/SQHdpaaVLSYojPv+BTy8Eg8K /z4wDGza7DkveMXrtPVMPoSEs6jKD+hlIErH5f2tkicEVJWoEMEDpiOwwN7fpn0ccQW6w VqLar2O2dyNfDnqmb/b+CSkV52j8BVFxrOjf3lLfgq+IcN6TC29AcWaHMVXqWqxlTEIR5 CF0FQ8zyVHGq+paaqBMZHka7YDR2ofNhpS3UmHrLwMiyJD5/B1mQeS1IU/dAREYa1gQ==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186151; b=OyQmHp7XQvZjdBkca7YUfvaYJSoJzI9t5v8UlOcJtx8Av/LHLPZv0Q7VHRd/jf4gDpVJ VKVxpOYHl2mf1X/0pbfwvHDZAPjgYLFqOUI98WcaP97/CiJqxJhikh5HeiFkOR/40hkqV CNu6rUnQGojjQv/g3HrUkN/3RiPoXDzkDYPAttz0KH/D32qX3X6vNIZdVNE9N2la6XREB 81z41BKX4+7JO/WWsaBdiawYgLTm5txhj/NJkdslThy8eX7F5j4REb/AH0ql2+uVMxvkk tNFSYY0ppaGMHncZYP6Jp18a81Mj9Ju15fe9LBFz/vkSsskqQ6nncGnk6Lp0kYDhFiw==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182039; b=TnthRLImP11tOz+rifw4tgK+rz3ElKymtY5OAZMZa8udnekvAJ/n8wr+prReQJShUX1C 1JNemF5aHBvYXaAGvuxjOp/VWPBDd+wgyPBbXnlaLOSew+GaJ5ZQZUoEJY2N01P+/s90K 7grIXdQbC9Vn836hGXKzIW5l3DvZ/hDFRDckeYe7r/3nGKByjXng3gIi/l7LFRzTwlUMR MBRojlNSF4p/NfmjREjXVnJ5nDgzo2utNj8PSqmfhfDzUN6Pgq9gSkHzyxyzrKJA8LRaG EioKh+Gkf4uaFa+Y7XR1VGyCc5frIdQfzUjKzAFSOJD3T88PlGBqYXHio+WSE0hPx/w==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/ILLCRXOC6L4NQJR2ELZ3FNJJJDXRA4XZ/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=HKf13h7b; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=eH1TVhFJ; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=2QampLXj; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-172
Project: Webform [1]
Project machine name: webform
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Default [2]
Vulnerability: Cross-site scripting
Affected versions: <6.2.12 || >=6.3.0 <6.3.1
CVE IDs: CVE-2026-96357
Description:
The Webform module allows site builders to create forms, collect submissions,
and configure access to forms and submission data. Form submissions may
include uploaded files.
The module does not sufficiently force certain uploaded file types to
download when served. Under certan site configurations, a file uploaded
through a webform could be rendered inline by a browser, resulting in a
cross-site scripting vulnerability.
This vulnerability is mitigated by the fact that a user with permission to
create or edit webforms must configure the form to allow the affected file
extensions, and a user must specifically open the uploaded file.
Solution:
Install the latest version:
* If you use the 6.2.x branch of Webform upgrade to Webform 6.2.12 [3].
* If you use the 6.3.x branch of Webform, upgrade to Webform 6.3.1 [4].
Reported By:
* Michael Maturi (michaelmaturi) [5]
Fixed By:
* Jacob Rockowitz (jrockowitz) [6]
* Lee Rowlands (larowlan) [7] of the Drupal Security Team
Coordinated By:
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/webform
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/webform/releases/6.2.12
[4] https://www.drupal.org/project/webform/releases/6.3.1
[5] https://www.drupal.org/u/michaelmaturi
[6] https://www.drupal.org/u/jrockowitz
[7] https://www.drupal.org/u/larowlan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3598060
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.