CVE-2026-55806 Details
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
A URL redirection vulnerability has been identified in Drupal Core, affecting versions prior to 10.5.12, 10.6.0 through 10.6.11, 11.2.0 through 11.2.14, 11.3.0 through 11.3.12, as well as all 11.0.x and 11.1.x versions. This vulnerability allows for open redirects to untrusted sites, which could be exploited for cache poisoning or to redirect users to attacker-controlled domains. The issue arises because the 'rebuild.php' front controller does not properly validate the Host header against trusted host patterns.
Users can update to the latest version of Drupal. For Drupal 11.3.x, update to Drupal 11.3.12. For Drupal 11.2.x, update to Drupal 11.2.14. For Drupal 10.6.x, update to Drupal 10.6.11. For Drupal 10.5.x, update to Drupal 10.5.12. Note that Drupal 11.1.x, 11.0.x, and Drupal 10.4.x and below are end-of-life and do not receive security coverage.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-core-2026-007 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | < 10.5.12 >= 10.6.0, < 10.6.11 >= 11.0.0, < 11.2.14 >= 11.3.0, < 11.3.12 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |