Startseite
  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche
Startseite › Newsfeed-Generator › Herkunft ›

Drupal PSA Security

Inhalt abgleichen
URL: https://www.drupal.org/security/psa
Aktualisiert: vor 1 Stunde 17 Minuten

Upcoming critical contributed project security release on September 23, 2026 - PSA-2026-09-21

21 September, 2026 - 11:56
Date: 2026-September-21Description: 
  • Updated 2026-09-22, 12:00 UTC, to document that the advisories in the release might be possible for more common configurations, and that other projects may have advisories.
  • Updated 2026-09-21, 19:00 UTC, to document that this is not covered by Drupal Steward.

There will be a security release for a widely used contributed module on September 23, 2026 between 17:00 and 21:00 UTC.

We are announcing this release in advance because the affected contributed module is used on a significant portion of Drupal sites, and the upcoming release will include a significant number of advisories.

The advisory with the highest risk score for the release is currently rated as critical. Other, less severe advisories in the release may be accessible to anonymous users, or result from default configurations.

Other contributed projects may also release advisories on the same date, possibly with more severe vulnerabilities. Drupal core is not affected.

Drupal Steward information

These releases will not be covered by Drupal Steward.

Advisories may be published in batches (a few at a time)

The current rate of advisories may require changes to our practices going forward:

  • The security team may publish advisories individually, at different times inside the window.
  • We will try to publish batches grouped by module.
  • We will announce in Slack when all planned releases for the day are complete.
  • We will release mailing list emails about the security updates together at the end of the window, to reduce the risk of site owners updating multiple times while advisories are still being published.

These changes are intended to make the process easier for the team and to make communication from the team easier to follow.

No special release procedures

The planned update does not require special release procedures.

Solution: 

Update, 2026-09-23 18:30 UTC: The Webform project has released the below 20 advisories today. Make note of the critical advisory SA-CONTRIB-2026-175, which has slightly increased severity than was originally noted in this public service announcement.

Other advisories than those below were published for other projects, so site owners should follow all normal update procedures.

  1. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-154
  2. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-155
  3. (Advisory numbers 156 and 157 were accidentally skipped in how we applied the numbering; these are not missing security advisories.)
  4. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-158
  5. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-159
  6. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-160
  7. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-161
  8. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-162
  9. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-163
  10. Webform - Moderately critical - Access bypass, Server-side request forgery - SA-CONTRIB-2026-164
  11. Webform - Less critical - Access bypass - SA-CONTRIB-2026-165
  12. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-166
  13. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-167
  14. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-168
  15. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-169
  16. Webform - Less critical - Denial of service - SA-CONTRIB-2026-170
  17. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-171
  18. Webform - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-172
  19. Webform - Less critical - Access bypass - SA-CONTRIB-2026-173
  20. Webform - Moderately critical - Access bypass - SA-CONTRIB-2026-174
  21. Webform - Critical - Remote Code Execution - SA-CONTRIB-2026-175
Coordinated By: 
  • Bram Driesen (bramdriesen) of the Drupal Security Team
  • Damien McKenna (damienmckenna) of the Drupal Security Team
  • Greg Knaddison (greggles) of the Drupal Security Team
  • Dave Long (longwave) of the Drupal Security Team
  • Moshe Weitzman (moshe weitzman) of the Drupal Security Team
  • Pierre Rudloff (prudloff) of the Drupal Security Team
  • Jess (xjm) of the Drupal Security Team
Kategorien: Drupal Security

Security advisory coverage removed - QA Accounts - PSA-2026-07-22

22 Juli, 2026 - 19:59
Date: 2026-July-22Description: 

QA Accounts enables you to login to a Drupal site using a well known username/password combination. When 1.0 was released, it also was marked for security coverage. The module prioritizes ease of use rather than security and is only intended to be used on sites that are not accessible on the internet (e.g. behind firewall or other protection). The maintainers are choosing to remove security coverage.

Solution: 

Ensure qa_accounts is not enabled on any publicly available site.

Reported By: 
  • Jordan Barnes (j-barnes)
Fixed By: 
  • Jakob P (japerry)
Kategorien: Drupal Security

Benutzeranmeldung

  • Registrieren
  • Neues Passwort anfordern

Aktive Forenthemen

  • Canvas Palette: Eine fertige Komponentenbibliothek für Drupal Canvas
  • Hilfe zu Updates oder Composer
  • Vergleich Drupal und Contao
  • [geloest] Blocks in Bootstrap nebeneinander darstellen und nicht untereinander
  • DrupalCamp Frankfurt 27-28 November 2026
  • Bitte mein Bentzerkonto löschen
  • Beim Aufruf einiger Inhalte erhalte ich folgende Fehlermeldung
  • Neuinstallation: vermutlich ein rewrite-Problem
  • Drupal CMS installieren
  • [erledigt]MP3 in Drupal 10 einbinden
  • (gelöst)Drupal 11 installieren
  • Titel ausblenden
Weiter

Neue Kommentare

  • Danke ich werde mir die
    vor 1 Woche 6 Tagen
  • Vielen Dank für Ihren
    vor 2 Wochen 2 Tagen
  • Composer ist sehr ratsam
    vor 2 Wochen 4 Tagen
  • Vielen Dank für den
    vor 3 Wochen 1 Stunde
  • Die alten CMS Vergleiche von contentmanager.de
    vor 3 Wochen 13 Stunden
  • Gut gemacht
    vor 3 Wochen 13 Stunden
  • Layout Builder etc. z.B. für Landing Pages
    vor 3 Wochen 13 Stunden
  • Links
    vor 3 Wochen 3 Tagen
  • Moin,wow, sehr gutes
    vor 3 Wochen 4 Tagen
  • Dass ist eine spannende
    vor 3 Wochen 4 Tagen

Statistik

Beiträge im Forum: 250316
Registrierte User: 20564

Neue User:

  • Robertspaft
  • drupalthemes
  • rofilm

» Alle User anzeigen

User nach Punkten sortiert:
wla9466
stBorchert6003
quiptime4972
Tobias Bähr4019
bv3924
ronald3857
md3717
Thoor3678
Alexander Langer3416
Exterior2903
» User nach Punkten
Zur Zeit sind 0 User und 12 Gäste online.

Drupal Security

  • Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
  • Smart Content - Moderately critical - Access bypass - SA-CONTRIB-2026-190
  • CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Combined image style - Moderately critical - Improper access control - SA-CONTRIB-2026-188
  • AI CKEditor - Moderately critical - Code execution via Twig templates - SA-CONTRIB-2026-187
Weiter

Hauptmenü

  • » Home
  • » Handbuch & FAQ
  • » Forum
  • » Übersetzungsserver
  • » Suche

Quicklinks I

  • Infos
  • Drupal Showcase
  • Installation
  • Update
  • Forum
  • Team
  • Verhaltensregeln

Quicklinks II

  • Drupal Jobs
  • FAQ
  • Drupal-Kochbuch
  • Best Practice - Drupal Sites - Guidelines
  • Drupal How To's

Quicklinks III

  • Tipps & Tricks
  • Drupal Theme System
  • Theme Handbuch
  • Leitfaden zur Entwicklung von Modulen

RSS & Twitter

  • Drupal Planet deutsch
  • RSS Feed News
  • RSS Feed Planet
  • Twitter Drupalcenter
Drupalcenter Team | Impressum & Datenschutz | Kontakt
Angetrieben von Drupal | Drupal is a registered trademark of Dries Buytaert.
Drupal Initiative - Drupal Association