Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • Date: Wed, 23 Sep 2026 17:21:52 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=oh7IuQDI; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=rvCo98Fo; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=oh7IuQDI; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=rvCo98Fo; arc=none smtp.remote-ip=54.240.27.35
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 0BFDB442E8
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 6C46A400AA
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790187082; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=wPLyxADYbxtDYK6XdaGqOPI7YomIHHdpJjnChhmtvKw=; b=hvtqvcs9RXpPAt4RZB9m0OHtWlviV1s00YHSMa4W5mauPpw0vV/tuxDVG7e/JKFjPTWP eDAMa/2IqZR/l8oF7aachGLqw0Tdeu3BnofLwfPy+vMXtLQhJYvfDnCCHHxRW8Yym60+D PpvlWstMyGvLfNm7EBqv3wg/w/HAPkeYrGnCdqBSvA/aPbHcu4RWfPR6kXxp6kkB5wcZ3 s/k8+S1WPhOTgjMM/wsJqYpP8bweQAnplGUw81pGV4rtHLyu1Ywb4K1JYUyCqTTZsZEcL EUUzHlhRf1jcgxaElQDfQJWagcHvhrmj1dXwRS4Cn0jc8gtxEXSxIFERuSSXoOxCk6w==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184113; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=LLuxOvj9YediXbzLv9b++fey3P0QB4XMn51KlhhqssI=; b=RzhOJzYIEX34+HUIWLJaS7+UzDTCbp+GgWBAMZ1Y43wmqakqsiZ81S+PaYek4/tQ/RRO h64hqSbApnzg8q9DswQC1YZFfvbVxtDsI4JS7wph/otijkoeQL3sagI3eT98ZAy43TqPA gHPYtf1rA/ZXSmFa+uRABxQM3wB9hEdAJq2d8mh/JHZ+bNLiJ9+nNSJTFP97R7phSxcR8 6Ct0hwHl0rXG+/q0iqVryvHbcPdDPPpyEwFK0fhSi5ByULsRWVVNoVQnctvPrm77wYQCb 7c3+GVTWW5+GvsXlRY2qKyz238AGt416KNJ3cWIQB7s24Plju84alcvBv28PtufYVug==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790187082; b=AiBOH8o1hb+a6PdON4d1QauYlcJnQGZYLrVzbr9TrKYnNmReawcl8AoD7tN8816tcc25 SX3HGP+eCA62T0LjgwLrD3wZW6voLKQOlrHPMVR88VNQbSCHkADBt+/ISzT0YGpRIEUsU HTS2YJ+Y/4/BUROtIkd7EFXdPDgEq8DLDSi+9IXSRUZTVUnRQudH/jWpwUhsvUv1qXjYa gHdNuKmi8RxrKt5xL/jgxj3vC2AMhkAk99b+Mh2WJ2Me2cR2yTTEgKE9t3wK9d49/B0xV pXg/hAzR3h4O24XWa62thrqQsB6JAGPaOhyhNVIZp9pBIc3WV47YeYGTImn1/44+3Sw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790184113; b=EgKnFeNGaU0PEnU20d6zCxJLm3gmP+t5pKDAikJd+1J13QQzP0kdgK8jkI49N17/F33k OUs2iCqaU1qsmjY8+5248+lX2skAdBUIWhZbPosM2vZHwqU4WE/QB4x2vYWnl5HITyGso 5dy75eVFb+aogXqTAoS04rVIenNBuaWcYTz3QVdWcxYE2mVPWSa2nTE2zzZOMlzeVIaJV iIx7YKplmwKMIPGU2v7bUNMiPhO60wJS/T1gmASbpFFbNZ+BCwlyiFnmsn/Nub5cRqNAz KR2Ib8Ex2C+nfDOAK7iY6hfi59muC9GbxInnVP9sjY2gkb6QM68KjdZlooPDA70B/HA==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/3JWWFCNBAJTLTIZTDU44TUGXWDFK3MR2/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=ghgfhswJ; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=oh7IuQDI; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=rvCo98Fo; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 2605:bc80:3010::133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-188

Project: Combined image style [1]
Project machine name: combined_image_style
Date: 2026-September-23
Security risk: *Moderately critical* 10 ∕ 25
AC:Basic/A:None/CI:None/II:None/E:Theoretical/TD:All [2]
Vulnerability: Improper access control

Affected versions: <1.0.7
CVE IDs: CVE-2026-96377
Description: 
This module enables you to combine multiple image styles into a single image
derivative.

The module does not sufficiently validate image style names when generating
image derivatives. Under certain circumstances, this allows anonymous users
to generate image derivatives without a valid token, potentially leading to a
denial of service.

Sites are affected simply by having the module installed, even when no
combined image styles are configured or in use.

This vulnerability is mitigated by the fact that only public files can be
targeted, and derivatives of private files are still protected by core's
token check.

Solution: 
Install the latest version:

* If you use the Combined image style module, upgrade to Combined image
style 1.0.7 [3].

Reported By: 
* Sven Decabooter (svendecabooter) [4]

Fixed By: 
* Sven Decabooter (svendecabooter) [5]
* Swan Kalata (akalata) [6] of the Drupal Security Team

Coordinated By: 
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Bram Driesen (bramdriesen) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [12]

[1] https://www.drupal.org/project/combined_image_style
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/combined_image_style/releases/1.0.7
[4] https://www.drupal.org/u/svendecabooter
[5] https://www.drupal.org/u/svendecabooter
[6] https://www.drupal.org/u/akalata
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/bramdriesen
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3622942

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang