CVE-2026-55807
published 2026-07-10CVE-2026-55807: Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0…
PriorityP414low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.22%
12.5th percentile
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| drupal | drupal | < 10.5.12 | 10.5.12 |
| drupal | drupal | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal | >= 11.0.0 < 11.2.14 | 11.2.14 |
| drupal | drupal | >= 11.3.0 < 11.3.12 | 11.3.12 |
| drupal | drupal_core | — | — |
| drupal | drupal_core | >= 0.0.0 < 10.5.12 | 10.5.12 |
| drupal | drupal_core | >= 0.0.0 < 11.0.* | 11.0.* |
| drupal | drupal_core | >= 0.0.0 < 11.1.* | 11.1.* |
| drupal | drupal_core | >= 10.6.0 < 10.6.11 | 10.6.11 |
| drupal | drupal_core | >= 11.2.0 < 11.2.14 | 11.2.14 |
| drupal | drupal_core | >= 11.3.0 < 11.3.12 | 11.3.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery.
ghsa_unreviewed·2026-07-11
CVE-2026-55807 CWE-918 Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery.
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
VulDB
Drupal up to 11.3.11 Core server-side request forgery
vuldb·2026-07-11
CVE-2026-55807 [LOW] Drupal up to 11.3.11 Core server-side request forgery
A vulnerability, which was classified as problematic, has been found in Drupal up to 11.3.11. Affected by this vulnerability is an unknown functionality of the component Core. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2026-55807. The attack is possible to be carried out remotely. No exploit exists.
Drupal
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
vendor_drupal·2026-06-17
CVE-2026-55807 [MEDIUM] Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Title: Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Vulnerability Type: Server-side request forgery
Description: The Media module comes with support for oEmbed. The oEmbed specification contains two discovery mechanisms, via providers.json and via URL discovery. The URL discovery code could be leveraged to trick Drupal into making server-side requests to any URL.
Solution: Install the latest version: Drupal 11 If you use Drupal 11.3.x, update to Drupal 11.3.12 . If you use Drupal 11.2.x, update to Drupal 11.2.14 . Drupal 10 If you use Drupal 10.6.x, update to Drupal 10.6.11 . If you use Drupal 10.5.x, update to Drupal 10.5.12 . Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. ( Drupal 8 and
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55807 drupal7: Drupal core: Server-Side Request Forgery vulnerability [fedora-all]
bugzilla·2026-07-13·CVSS 3.1
CVE-2026-55807 [LOW] CVE-2026-55807 drupal7: Drupal core: Server-Side Request Forgery vulnerability [fedora-all]
CVE-2026-55807 drupal7: Drupal core: Server-Side Request Forgery vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
Discussion:
Drupal 7 End of Life 2025-01-05 (https://www.drupal.org/about/drupal-7/d7eol/partners)
It has been retired from all EPEL and from F44+
The version in F43 (7.103) is the latest ver
Bugzilla
CVE-2026-55807 Drupal core: Drupal core: Server-Side Request Forgery vulnerability
bugzilla·2026-07-10·CVSS 3.1
CVE-2026-55807 [LOW] CVE-2026-55807 Drupal core: Drupal core: Server-Side Request Forgery vulnerability
CVE-2026-55807 Drupal core: Drupal core: Server-Side Request Forgery vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
2026-07-10
Published