SA-CONTRIB-2026-216: Critical severity drupal/restrict_route_by_ip vulnerability
This module enables you to restrict access to routes by IP address. The module doesn't reliably restrict a subset of dynamic routes, leading to an access bypass vulnerability. The impact depends on how a site uses this module and whether it has any routes that are dynamic.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/restrict_route_by_ipto a version that resolves this vulnerability.Fixed in 2.0.1Fixed in 1.3.1