Intel

AIKIDO-2026-788875

drupal/core is vulnerable to Server-side Request Forgery (SSRF)

Server-side Request Forgery (SSRF)CVE-2026-55807 Published Jun 22, 2026

49

Medium Risk

This Affects:

PHPdrupal/core
0.0.0 - 10.5.11
Fixed in 10.5.12
10.6.0 - 10.6.10
Fixed in 10.6.11
11.0.0 - 11.2.13
Fixed in 11.2.14
11.3.0 - 11.3.11
Fixed in 11.3.12
Are you affected? Scan for Free

TL;DR

The Media module's oEmbed support — which implements the spec's two discovery mechanisms, providers.json and URL discovery — contains a flaw in the URL discovery logic that can be abused to trick Drupal into issuing server-side requests to arbitrary attacker-controlled URLs, resulting in a Server-Side Request Forgery (SSRF) vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/core is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.

How to fix this

Upgrade the drupal/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform