Intel

AIKIDO-2026-788875

drupal/core is vulnerable to Server-side Request Forgery (SSRF)

Server-side Request Forgery (SSRF)CVE-2026-55807 Published Yesterday

49

Medium Risk

This Affects:

PHPdrupal/core
0.0.0 - 10.5.11
Fixed in 10.5.12
10.6.0 - 10.6.10
Fixed in 10.6.11
11.0.0 - 11.2.13
Fixed in 11.2.14
11.3.0 - 11.3.11
Fixed in 11.3.12
Are you affected? Scan for Free

TL;DR

The Media module's oEmbed support — which implements the spec's two discovery mechanisms, providers.json and URL discovery — contains a flaw in the URL discovery logic that can be abused to trick Drupal into issuing server-side requests to arbitrary attacker-controlled URLs, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.

How to fix this

Upgrade the drupal/core library to the patch version.