PT-2026-97669 · Packagist · Drupal/Combined Image Style
CVE-2026-96377
·
Publicado
2026-09-23
·
Atualizado
2026-09-23
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
This module enables you to combine multiple image styles into a single image derivative.
The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.
Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.
This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Drupal/Combined Image Style