Junglewise Threat Intelligence

CVE-2026-96365: Drupal Webform denial of service via unvalidated token parameter

CVE-2026-96365 · Severity: info · Published 2026-09-23

Technologies: Drupal Webform, Packagist:Https://Packages.Drupal.Org/8 Drupal/Webform. Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Webform module for Drupal allows site builders to create and manage online forms. When a form is exposed to anonymous visitors, a malicious attacker can send a crafted request with an improperly validated token parameter that forces the server to consume excessive resources, causing the website to become unavailable or slow to respond. This affects sites using specific Webform configurations.

Technical details

The Webform module fails to properly validate an optional token query parameter before processing requests, allowing an unauthenticated attacker to trigger resource exhaustion via a specially crafted request. The vulnerability exists in configurations where Webforms are rendered for anonymous visitors. A patch is available in versions 6.2.12, 6.3.1, and later.

Affected products

  • Drupal Webform <6.2.12, >=6.3.0 <6.3.1

Timeline

  • 2026-09-23: disclosed

References

Related threats