Install

To start a new Drupal project with version 10.4.9:

To update your site and all dependencies to the latest version of Drupal:

To update your site to this specific release:
Pinning to a specific release may make it more challenging to update your site in future, see composer documentation for managing pinned versions

Using Composer to manage Drupal site dependencies

Downloads

Download tar.gz 20.18 MB
MD5: fc05beeef5981bbd551974202f493876
SHA-1: b0b856ed90aee2454dce97d7edd1331895a6cb7f
SHA-256: ad4e199644288f5728d2876720a5a97fe822f0544bc28da22b9eb0a340f3d8c0
Download zip 33.34 MB
MD5: ff87909197b69548acf01df92ad36693
SHA-1: 82cdb53e9356620d7bb08a1fc81d66e1c5d8335f
SHA-256: 2fe00fc3d1c9f19133b3df92b66f411a596929f2a1f49bd9a61bebd1d8049fce

Security issues fixed

Release notes

This is a security release of the Drupal 10 series.

This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:

Important update information

  • SA-CORE-2025-005 removes a feature of an underlying library where request attributes can be manipulated. It is possible that some sites are actually relying on this feature. In this case, the behavior can be replicated by implementing a custom stack middleware to alter the incoming request.

  • This release updates minimum versions of Symfony Framework libraries. The updated libraries include a fix for CVE-2025-64500. Drupal does not expose this vulnerability, but the update is included as a hardening for other applications that may extend the library directly.

Which release do I choose? Security coverage information

  • Drupal 10.4.x will receive security coverage until December 2025 when Drupal 10.6.0 is released and sites should plan to update to Drupal 10.5 or higher by December 2025.
  • Sites on Drupal 11.2.x should update immediately to Drupal 11.2.8.
  • Sites on Drupal 11.1.x should update immediately to Drupal 11.1.9.
  • Sites on Drupal 10.5.x should update immediately to Drupal 10.5.6.
  • Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage.

Other changes in this release

Additional test-only fixes are included in the release:

  • Issue #3539331 by dww, godotislate, nicxvan: Incorrect warning for system requirements for APCu memory
  • Issue #3539366 by dimitriskr, andypost, godotislate: Default DB transaction isolation set to read-committed breaks InstallerIsolationLevelExistingSettingsTest test
  • Issue #3484845 by mstrelan, catch, acbramley: [random test failure] ImageUrlProviderTest::testResize

What’s next?

  1. Learn how to install Drupal
  2. Learn how to update Drupal
  3. Extend Drupal to do more
  4. Get training
  5. Check out what others built
Created by: xjm
Created on: 12 Nov 2025 at 23:33 UTC
Last updated: 13 Nov 2025 at 00:11 UTC
Security update
Insecure
Unsupported

Other releases