Drupal core – Moderately critical – Server-side request forgery – SA-CORE-2026-008

SecurityVulns

Project: Drupal coreDate: 2026-June-17Security risk: Moderately critical 10 ∕ 25 AC:Basic/A:User/CI:Some/II:None/E:Theoretical/TD:DefaultVulnerability: Server-side request forgeryAffected versions: <10.5.12 || >=10.6.0 <10.6.11 || >=11.2.0 <11.2.14 || >=11.3.0 <11.3.12 || 11.0.* || 11.1.*CVE IDs: CVE-2026-55807Description: The Media module comes with support for oEmbed. The oEmbed specification contains two discovery mechanisms, via providers.json and via URL discovery.
The URL discovery code could be leveraged to trick Drupal into making server-side requests to any URL.Solution: Install the latest version:
Drupal 11

If you use Drupal 11.3.x, update to Drupal 11.3.12.
If you use Drupal 11.2.x, update to Drupal 11.2.14.

Drupal 10

If you use Drupal 10.6.x, update to Drupal 10.6.11.
If you use Drupal 10.5.x, update to Drupal 10.5.12.

Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage. (Drupal 8 and Drupal 9 have both reached end-of-life.)
Required site changes for URL discovery
Most users of the oEmbed functionality in Drupal likely use providers.json to define known providers (such as YouTube and Vimeo) for embedding content.
If you are using URL discovery, you now need to set a list of trusted oEmbed discovery hosts in settings.php.
This is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com.
$settings[‘media_oembed_discovery_trusted_host_patterns’] = [
‘^example.com$’,
];
Reported By: 
Hamed Kohi (0xhamy)
assaf alassaf (ama62)
Albert Skibinski (askibinski)
Jon Minder (ayalon)
Lautaro Casanova (betah4k)
Gabe Sullice (gabesullice)
John Morahan (john morahan)
Michael Winser (michaelwinser)
nbanderson
offensive-ai
Francesco Placella (plach)
quynh ho (qquynh)
Himanshu Anand (unknownhad)
Fixed By: 
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
Adam G-H (phenaproxima)
Sean Blommaert (seanb)
Coordinated By: 
Benji Fisher (benjifisher) of the Drupal Security Team
cilefen (cilefen) of the Drupal Security Team
Damien McKenna (damienmckenna) of the Drupal Security Team
Mori Sugimoto (dokumori) of the Drupal Security Team
Greg Knaddison (greggles) of the Drupal Security Team
Lee Rowlands (larowlan) of the Drupal Security Team
Dave Long (longwave) of the Drupal Security Team
Drew Webber (mcdruid) of the Drupal Security Team
James Gilliland (neclimdul) of the Drupal Security Team
Juraj Nemec (poker10) of the Drupal Security Team
Jess (xjm) of the Drupal Security TeamSecurity advisoriesRead More