SA-CORE-2026-008: Critical severity Drupal Drupal vulnerability
The Media module comes with support for oEmbed. The oEmbed specification contains two discovery mechanisms, via providers.json and via URL discovery. The URL discovery code could be leveraged to trick Drupal into making server-side requests to any URL.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.3.12Fixed in 11.2.14Fixed in 10.6.11Fixed in 10.5.12 - Upgrade
Upgrade
Drupal (Media module)to a version that resolves this vulnerability.Fixed in 11.3.12 - Upgrade
Upgrade
Drupal (Media module)to a version that resolves this vulnerability.Fixed in 11.2.14 - Upgrade
Upgrade
Drupal (Media module)to a version that resolves this vulnerability.Fixed in 10.6.11 - Upgrade
Upgrade
Drupal (Media module)to a version that resolves this vulnerability.Fixed in 10.5.12
Event History
Frequently Asked Questions
What is the severity of SA-CORE-2026-008?
The severity of SA-CORE-2026-008 is critical with a CVSS score of 9.
How do I fix SA-CORE-2026-008?
To fix SA-CORE-2026-008, update your Drupal installation to the latest version that includes the security patch.
What is the impact of SA-CORE-2026-008?
The impact of SA-CORE-2026-008 allows an attacker to exploit server-side requests to any URL, potentially leading to sensitive data exposure.
Which versions of Drupal are affected by SA-CORE-2026-008?
SA-CORE-2026-008 affects all versions of Drupal containing the Media module that supports oEmbed.
When was SA-CORE-2026-008 published?
SA-CORE-2026-008 was published on June 17, 2026.