Closed (fixed)
Project:
Drupal Security Team
Version:
7.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
15 Dec 2025 at 23:28 UTC
Updated:
9 Apr 2026 at 21:20 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
gregglesThanks aangel.
I'll adjust the status since there is a file to review.
Comment #3
aangel commentedWhoops, forgot that. Thanks.
Comment #4
gregglesOK, I reserved CVE-2026-0748 for this.
Comment #5
gregglesStill working on this? We should either publish the details or somehow stop using this CVE (e.g. reject it)
Comment #6
aangel commentedYes, have a new entry ready with the following changes:
1. Uses the ID.
2. Now uses D7-style version numbers.
3. Sets the package collection to https://www.drupal.org/project/i18n
4. I've added a link to our directory entry.
5. I was unable to find an entry in the Tag1 directory.
Comment #7
gregglesOK, thanks.
I found this page for tag1 which I can add as a related article at the time of publishing.
Comment #8
gregglesThe page: https://d7es.tag1.com/node/86
Comment #9
aangel commentedThey appear to have a bug or content issue for this entry because when I select i18n in their drop-down, I get an empty response.
https://d7es.tag1.com/security-advisories?field_project_target_id=70
So roger for that link.
Comment #10
gregglesThat's odd - it shows in the list for me, but definitely could be some kind of bug.
Comment #11
aangel commentedSorted it out. The dropdown includes the module entry for both Announcements and Security Advisories but produces a result only for Announcements.
I've added the Tag1 entry and set the date to their published date (June 11, 2025).
Comment #12
aangel commentedBumping.
Comment #13
gregglesI changed the versions to be custom instead of semver and published this. Thanks!