drupal/core is vulnerable to Deserialization of Untrusted Data
78
High Risk
SA-CORE-2019-003 blocked direct web-service writes to serialized fields, but a JSON:API gap remained: an attacker with JSON:API write permission could potentially trigger PHP Object Injection by writing to an entity reference field that stores a serialized property. This is low-risk in practice — no Drupal core field type fits the vulnerable pattern, such field types are rare even in contributed/custom code, and JSON:API write access is off by default (it must be explicitly enabled via config or a module) — but this update protects all such fields regardless, with no changes needed in contributed modules.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant