CVE-2026-55806
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
5.9
MEDIUM
CVSS 3.1
EPSS 0.21%
Description
Drupal core ships a `rebuild.php` front controller that can be used to rebuild Drupal (clearing the caches and rebuilding the container) when the site is in an unexpected condition. This script doesn't correctly check the Host header against the list of trusted host patterns. This could result in cache poisoning or a redirect to an attacker-controlled domain.
How to fix CVE-2026-55806
To remediate CVE-2026-55806, upgrade the affected package to a fixed version below.
- —upgrade to 10.5.12 or later
- —upgrade to 10.5.12 or later
Is CVE-2026-55806 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 10.5.12, >= 10.6.0, < 10.6.11, >= 11.0.0, < 11.2.14, >= 11.3.0, < 11.3.12
- from 0, < 10.5.12 | >= 10.6.0, < 10.6.11 | >= 11.2.0, < 11.2.14 | >= 11.3.0, < 11.3.12 | >= 11.0.0, < 11.1.0 | >= 11.1.0, < 11.2.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |