Executive brief
The 'Brute force attack protection' module for Drupal has been marked as unsupported due to an unpatched critical security vulnerability. This module is intended to manage login security, but the current flaw could allow an attacker to compromise the site's integrity or availability. Because the maintainer has not provided a fix, the Drupal security team recommends uninstalling the module immediately to prevent potential exploitation.
Technical details
The Drupal security team has issued a critical advisory (SA-CONTRIB-2026-047) for the 'Brute force attack protection' (bfap_sb) module. While the specific vulnerability class was not detailed in the public advisory beyond being 'Critical', the module has been marked as unsupported because the maintainer failed to resolve the underlying security issue. The advisory indicates a high risk to confidentiality, integrity, and availability. Given the lack of a patch, the only recommended mitigation is to completely uninstall the module and seek an alternative solution for brute force protection.
Affected products
- Drupal Brute force attack protection (bfap_sb) All versions
Timeline
- 2026-06-10: advisory: Drupal security team marks project unsupported via SA-CONTRIB-2026-047
- 2026-07-10: disclosed: CVE-2026-11915 published