PT-2026-107748 · Packagist · Drupal/Restrict Route By Ip

CVE-2026-107255

·

Published

2026-10-07

·

Updated

2026-10-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables you to restrict access to routes by IP address.
The module doesn't reliably restrict a subset of dynamic routes, leading to an access bypass vulnerability. The impact depends on how a site uses this module and whether it has any routes that are dynamic.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-107255
DRUPAL-CONTRIB-2026-216

Affected Products

Drupal/Restrict Route By Ip