Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Michael Winser

#29766of 56,330
9Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-50608
5.9
2026-06-17
Drupal · Drupal · CVE-2026-55806
**Name of the Vulnerable Software and Affected Versions** Drupal core (affected versions not specified) **Description** The `rebuild.php` front controller, used to clear caches and rebuild the container when a site is in an unexpected condition, fails to correctly validate the Host header against trusted host patterns. This flaw can lead to cache poisoning, where a cache is filled with a malicious response, or an open redirect, which sends users to an attacker-controlled domain. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-50609
3.1
2026-06-17
Drupal · Drupal · CVE-2026-55807
**Name of the Vulnerable Software and Affected Versions** Drupal core (affected versions not specified) **Description** The Media module supports oEmbed, which utilizes two discovery mechanisms: `providers.json` and URL discovery. The URL discovery code can be exploited to trick the system into making unauthorized server-side requests to any arbitrary URL. This is a Server-Side Request Forgery (SSRF), a flaw where an attacker can force a server to send requests to an unintended location. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.