Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
10 Dec 2025 at 23:38 UTC
Updated:
11 Feb 2026 at 18:59 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
gregglesOK, I reserved CVE-2026-0749 for this.
Comment #3
gregglesForgot to mark needs work for publishing the page and updating the json to include the CVE id and the link.
Comment #4
aangel commentedAttached is the updated JSON:
• added CVE ID
• versions conform to D7 style
• confirmed exploit is present from >=7.x-1.0 <=7.x-1.22 and >=7.x-2.0-alpha1 <=7.x-2.0-alpha8
• however, to be consistent with the rules for advisories, I did not include the 7.x-2.x branch for this CVE update since the branch contains only alphas (Tag1 released a version for 7.x-2.x; HeroDevs did not)
• used the date Tag1 published their fix (May 14, 2025)
• added two third-party reference URLs (HeroDevs and Tag1)
Comment #5
gregglesThis generally LGTM. Thanks for the explanations.
Comment #6
gregglesOK, I published this one. Thanks for your help.