PT-2026-97669 · Packagist · Drupal/Combined Image Style

CVE-2026-96377

·

Publicado

2026-09-23

·

Atualizado

2026-09-23

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This module enables you to combine multiple image styles into a single image derivative.
The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.
Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.
This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-96377
DRUPAL-CONTRIB-2026-188

Produtos afetados

Drupal/Combined Image Style