CVE-2026-55806
published 2026-07-10CVE-2026-55806: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.34%
26.8th percentile
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | < 10.5.12 | 10.5.12 |
| drupal | drupal | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal | >= 11.0.0 < 11.2.14 | 11.2.14 |
| drupal | drupal | >= 11.3.0 < 11.3.12 | 11.3.12 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.5.12 | 10.5.12 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal_core | >= 11.2.0 < 11.2.14 | 11.2.14 |
| drupal | drupal_core | >= 11.3.0 < 11.3.12 | 11.3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing.
ghsa_unreviewed·2026-07-11
CVE-2026-55806 CWE-601 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
VulDB
Drupal core up to 11.3.11 URL redirect
vuldb·2026-07-11
CVE-2026-55806 [LOW] Drupal core up to 11.3.11 URL redirect
A vulnerability described as problematic has been identified in Drupal core up to 11.3.11. This affects an unknown function of the component URL. Executing a manipulation can lead to open redirect.
The identification of this vulnerability is CVE-2026-55806. The attack may be launched remotely. There is no exploit available.
Drupal
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
vendor_drupal·2026-06-17
CVE-2026-55806 [LOW] Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Title: Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Vulnerability Type: Cache poisoning and open redirect
Description: Drupal core ships a rebuild.php front controller that can be used to rebuild Drupal (clearing the caches and rebuilding the container) when the site is in an unexpected condition. This script doesn't correctly check the Host header against the list of trusted host patterns. This could result in cache poisoning or a redirect to an attacker-controlled domain.
Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you use Drupal 11.2.x, update to Drupal 11.2.14 . Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.11 . If you use Drupal 10.5.x, update to Drupal 10.5.12 . Drupal 11.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-10
Published