Executive brief
The Webform module for Drupal allows site builders to create and manage online forms. When a form is exposed to anonymous visitors, a malicious attacker can send a crafted request with an improperly validated token parameter that forces the server to consume excessive resources, causing the website to become unavailable or slow to respond. This affects sites using specific Webform configurations.
Technical details
The Webform module fails to properly validate an optional token query parameter before processing requests, allowing an unauthenticated attacker to trigger resource exhaustion via a specially crafted request. The vulnerability exists in configurations where Webforms are rendered for anonymous visitors. A patch is available in versions 6.2.12, 6.3.1, and later.
Affected products
- Drupal Webform <6.2.12, >=6.3.0 <6.3.1
Timeline
- 2026-09-23: disclosed