CVE-2026-55808 Details
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.
A cross-site scripting (XSS) vulnerability has been identified in Drupal Core. This issue arises from improper validation of uploaded image files via the JSON:API and REST modules. While the validation checks the file extension, it fails to verify the MIME type, potentially allowing malicious users to upload non-image files. In certain web server configurations, these files could be served with their actual MIME type instead of an image type, leading to XSS or other unexpected behaviors. The vulnerability affects Drupal Core versions prior to 10.5.12, 10.6.0 through 10.6.11, 11.2.0 through 11.2.14, 11.3.0 through 11.3.12, and all 11.0.* and 11.1.* versions.
Users can update to the latest version of Drupal. For Drupal 11, those on versions 11.3.x should update to 11.3.12, and those on 11.2.x should update to 11.2.14. For Drupal 10, users on 10.6.x should update to 10.6.11, and those on 10.5.x should update to 10.5.12. Versions 11.1.x, 11.0.x, and Drupal 10.4.x and below are end-of-life and do not receive security coverage.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-core-2026-009 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| drupal drupal | < 10.5.12 >= 10.6.0, < 10.6.11 >= 11.0.0, < 11.2.14 >= 11.3.0, < 11.3.12 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |