Drupal core – Moderately critical – Denial of Service – SA-CORE-2025-005

SecurityVulns

Project: Drupal coreDate: 2025-November-12Security risk: Moderately critical 13 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:AllVulnerability: Denial of ServiceAffected versions: >= 8.0.0 < 10.4.9 || >= 10.5.0 < 10.5.6 || >= 11.0.0 < 11.1.9 || >= 11.2.0 < 11.2.8CVE IDs: CVE-2025-13080Description: Drupal Core has a rarely used feature, provided by an underlying library, which allows certain attributes of incoming HTTP requests to be overridden.
This functionality can be abused in a way that may cause Drupal to cache response data that it should not. This can lead to legitimate requests receiving inappropriate cached responses (cache poisoning).
This could be exploited in various ways:

Broken rendering of some pages
Unstyled or malformatted pages
Adverse impacts on client-side functionality

Changes are being made in the underlying library which will mitigate this problem, but in the meantime Drupal core has been hardened to protect against this vulnerability.Solution: Install the latest version:

If you are using Drupal 10.4, update to Drupal 10.4.9.
If you are using Drupal 10.5, update to Drupal 10.5.6.
If you are using Drupal 11.1, update to Drupal 11.1.9.
If you are using Drupal 11.2, update to Drupal 11.2.8.

Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)Reported By: 
Dragos Dumitrescu (dragos-dumi)
yasser ALLAM (inzo_)
Nils Destoop (nils.destoop)
Sven Decabooter (svendecabooter)
zhero
Fixed By: 
Alex Pott (alexpott) of the Drupal Security Team
catch (catch) of the Drupal Security Team
cilefen (cilefen) of the Drupal Security Team
Jen Lampton (jenlampton), provisional member of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Nils Destoop (nils.destoop)
Juraj Nemec (poker10) of the Drupal Security Team
Ra Mänd (ram4nd), provisional member of the Drupal Security Team
Jess (xjm) of the Drupal Security Team
Coordinated By: 
catch (catch) of the Drupal Security Team
Greg Knaddison (greggles) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security Team
Jess (xjm) of the Drupal Security TeamSecurity advisoriesRead More