May we please get a CVE ID reserved for the Icon API exploit described in https://security.drupal.org/node/184480?
Attached is the CVE json that will be updated with:
• the HeroDevs directory URL when it's ready
• the Tag1 URL if it's ready
The rating I've given it is Medium (5.1).
| Comment | File | Size | Author |
|---|---|---|---|
| #3 | CVE-2026-16132.json_.txt | 6.24 KB | aangel |
| icon-title-wrapper.json_.txt | 5.91 KB | aangel |
Comments
Comment #2
gregglesComment #3
aangel commentedThis updated JSON has both URLs now and the assigned CVE ID. Back to Needs review.