Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
View online: https://www.drupal.org/sa-core-2026-011 Project: Drupal core [1] Date: 2026-July-15 Security risk: *Moderately critical* 14 ∕ 25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2] Vulnerability: Cross-site scripting Affected versions: >=11.2.0 CVE IDs: CVE-2026-15917 Description: Drupal core 11.2 and above integrate the HTMX JavaScript library. Drupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability. The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes. Solution: Install the latest version: *Drupal 11* * If you use Drupal 11.4.x, update to Drupal 11.4.4 [3]. * If you use Drupal 11.3.x, update to Drupal 11.3.14 [4]. * Drupal 11.2.x and below are end-of-life and do not receive security coverage. *Drupal 10* * Drupal 10 core is not affected. However, certain contributed modules may be affected, so a Drupal 10.6 fix is included as hardening. Drupal 8 [5] and Drupal 9 [6] have both reached end-of-life. Reported By: * Pierre Rudloff (prudloff) [7] of the Drupal Security Team Fixed By: * Shawn Duncan (fathershawn) [8] * Pierre Rudloff (prudloff) [9] of the Drupal Security Team Coordinated By: * catch (catch) [10] of the Drupal Security Team * Lee Rowlands (larowlan) [11] of the Drupal Security Team * Dave Long (longwave) [12] of the Drupal Security Team * Jess (xjm) [13] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [14] [1] https://www.drupal.org/project/drupal [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/drupal/releases/11.4.4 [4] https://www.drupal.org/project/drupal/releases/11.3.14 [5] https://www.drupal.org/psa-2021-06-29 [6] https://www.drupal.org/psa-2023-11-01 [7] https://www.drupal.org/u/prudloff [8] https://www.drupal.org/u/fathershawn [9] https://www.drupal.org/u/prudloff [10] https://www.drupal.org/u/catch [11] https://www.drupal.org/u/larowlan [12] https://www.drupal.org/u/longwave [13] https://www.drupal.org/u/xjm [14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....
participants (1)
-
security-news@drupal.org