May we please get a CVE ID reserved for the Icon API exploit described in https://security.drupal.org/node/184480?

Attached is the CVE json that will be updated with:
• the HeroDevs directory URL when it's ready
• the Tag1 URL if it's ready

The rating I've given it is Medium (5.1).

Comments

aangel created an issue. See original summary.

greggles’s picture

Title: Request for CVE ID for Icon » Publish CVE-2026-16132 for Icon
Status: Active » Needs work
aangel’s picture

Status: Needs work » Needs review
StatusFileSize
new6.24 KB

This updated JSON has both URLs now and the assigned CVE ID. Back to Needs review.