Executive brief
Drupal, a popular website management platform, contains a security flaw in its maintenance script used for rebuilding site caches. An attacker can manipulate web requests to trick the system into redirecting users to malicious websites or corrupting the site's temporary data storage. This could be used in phishing campaigns to steal user credentials or to display unauthorized content to visitors.
Technical details
An open redirect and cache poisoning vulnerability exists in Drupal core's rebuild.php front controller. The script fails to properly validate the HTTP Host header against the configured list of trusted host patterns. A remote attacker can exploit this by sending a specially crafted request with a malicious Host header. This can lead to the application generating redirects to attacker-controlled domains or poisoning the internal cache with incorrect host information, potentially affecting subsequent legitimate user requests. Patches are available in Drupal versions 10.5.12, 10.6.11, 11.2.14, and 11.3.12.
Affected products
- Drupal Drupal core <10.5.12, 10.6.x < 10.6.11, 11.0.x, 11.1.x, 11.2.x < 11.2.14, 11.3.x < 11.3.12
Timeline
- 2026-06-17: advisory: Drupal security advisory SA-CORE-2026-007 published
- 2026-07-10: disclosed: CVE-2026-55806 published to NVD