CVE-2026-55807 Details
Description
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
A server-side request forgery (SSRF) vulnerability exists in Drupal Core. This issue affects Drupal Core versions prior to 10.5.12, 10.6.0 through 10.6.11, 11.2.0 through 11.2.14, 11.3.0 through 11.3.12, as well as all versions in the 11.0.x and 11.1.x series. The vulnerability arises in the Media module, which supports oEmbed. The oEmbed specification allows for URL discovery that could be exploited to make unauthorized server-side requests to any URL.
Users should update to the latest version of Drupal. For Drupal 11.3.x, update to Drupal 11.3.12. For Drupal 11.2.x, update to Drupal 11.2.14. For Drupal 10.6.x, update to Drupal 10.6.11. For Drupal 10.5.x, update to Drupal 10.5.12. Drupal 11.1.x, Drupal 11.0.x, and Drupal 10.4.x and below are end-of-life and do not receive security coverage.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-core-2026-008 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | < 10.5.12 >= 10.6.0, < 10.6.11 >= 11.0.0, < 11.2.14 >= 11.3.0, < 11.3.12 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |