Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030
| Source of Advisories | https://www.drupal.org/security/ |
| Source of Advisories | https://www.drupal.org/security/ |
Automated Logout - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-030
Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-029
AI (Artificial Intelligence) - Moderately critical - Information Disclosure - SA-CONTRIB-2026-028
OpenID Connect / OAuth client - Less critical - Access bypass - SA-CONTRIB-2026-027
OpenID Connect / OAuth client - Moderately critical - Access bypass - SA-CONTRIB-2026-026
OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025
RE: https://mastodon.social/@drupalinfra/116166360994376777
There is a delay in delivering emails announcing today's advisories due to the drupal.org data center migration. See below for more details.
Google Analytics GA4 - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-024
Calculation Fields - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-023
AJAX Dashboard - Critical - Access bypass - SA-CONTRIB-2026-022