Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
5 Dec 2025 at 18:44 UTC
Updated:
11 Feb 2026 at 22:29 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
gregglesThanks. Acknowledging I've seen this and adjusting status to needs review so others know its time for that.
Comment #3
gregglesOK, I reserved CVE-2026-0750 for this.
Comment #4
aangel commentedI've attached a new version with the following changes:
• set the date to the publish date from Tag1 because they got it out first (May 2025)
• changed the Package collection URL to the module URL
• added our reference URL along with Tag1's; both tagged as 3rd-party vendor advisory
• no change to the description
Comment #5
aangel commentedBump. Ready to go?
Comment #6
gregglesThanks for the explanations in #4.
I made a few tweaks and published this.
* adjusting versions to 7.x style custom
* adding www on the package collection URL
* To be consistent with prior CVEs, the vendor should be "Drupal" not "Drupal community"
* Following previous examples - using the auto-generated description.
Those will be good things to double check for future CVEs.
Comment #8
aangel commented"Those will be good things to double check for future CVEs."
Will do.
(btw, we aligned on using the D7 version number style after this was submitted.)
Comment #9
greggles> (btw, we aligned on using the D7 version number style after this was submitted.)
I wondered about that. Thanks for pointing it out.