May we please get a CVE ID reserved for the View Reference Filter exploit described in https://security.drupal.org/node/184441?

Attached is the CVE json that will be updated with:
• the HeroDevs directory URL when it's ready

Current properties:
• it has Tag1's URL already
• date is set Tag1's release

The rating I've given it is Medium (6.9), which aligns with Tag1's "moderately critical."

Comments

aangel created an issue. See original summary.

greggles’s picture

Title: Request for CVE ID for Views Reference Filter (enttityreference_filter) » Publish CVE-2026-16136 for Views Reference Filter (enttityreference_filter)
Category: Support request » Task
Status: Active » Needs work

Moving to "needs work" for the Herodevs post to be made and added to this and and then I can publish it.

aangel’s picture

Status: Needs work » Needs review

Greg, I need the CVE ID before I can publish it.

greggles’s picture

Sure, the CVE is CVE-2026-16136