drupal/core is vulnerable to Host Validation Bypass
42
Medium Risk
Drupal core includes rebuild.php, a front controller used to recover sites stuck in a broken state by clearing caches and rebuilding the service container — but it fails to validate the incoming Host header against the site's configured trusted host patterns, allowing an attacker to supply an arbitrary Host value that gets reflected into cache keys or redirect targets, opening the door to cache poisoning or redirection to an attacker-controlled domain.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Host Validation Bypass in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant