CVE-2026-55807: Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0., from 0.0.0 to 11.1..
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55807?
CVE-2026-55807 is classified as moderately critical due to its server-side request forgery vulnerability.
How do I fix CVE-2026-55807?
To fix CVE-2026-55807, update Drupal core to a version that is not affected by this SSRF vulnerability.
Which Drupal core versions are affected by CVE-2026-55807?
CVE-2026-55807 affects Drupal core versions from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, and from 0.0.0 to 11.1.*.
What type of vulnerability is CVE-2026-55807?
CVE-2026-55807 is a server-side request forgery (SSRF) vulnerability.
When was CVE-2026-55807 published?
CVE-2026-55807 was published on July 10, 2026.