CVE-2026-55807

Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*.


We have discovered 180,897 live websites that are affected by CVE-2026-55807.

Run a Free Instant Scan




Affected Software

Product  Drupal
Category Content Management System
Vulnerable Domains180,897 live websites (88% of Drupal install base)
Vulnerable Versions
  • from 0 through 10.5.12
  • from 10.6 through 10.6.11
  • from 11.2 through 11.2.14
  • from 11.3 through 11.3.12
Vulnerable Versions Count311 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Jul 10, 2026
  • Updated - Jul 13, 2026

Credits

  • Hamed Kohi (0xhamy) (finder)
  • assaf alassaf (ama62) (finder)
  • Albert Skibinski (askibinski) (finder)
  • Jon Minder (ayalon) (finder)
  • Lautaro Casanova (betah4k) (finder)
  • Gabe Sullice (gabesullice) (finder)
  • John Morahan (john morahan) (finder)
  • Michael Winser (michaelwinser) (finder)
  • nbanderson (finder)
  • offensive-ai (finder)
  • Francesco Placella (plach) (finder)
  • quynh ho (qquynh) (finder)
  • Himanshu Anand (unknownhad) (finder)
  • Lee Rowlands (larowlan) (remediation developer)
  • Dave Long (longwave) (remediation developer)
  • Drew Webber (mcdruid) (remediation developer)
  • Adam G-H (phenaproxima) (remediation developer)
  • Sean Blommaert (seanb) (remediation developer)
  • Benji Fisher (benjifisher) (coordinator)
  • cilefen (cilefen) (coordinator)
  • Damien McKenna (damienmckenna) (coordinator)
  • Mori Sugimoto (dokumori) (coordinator)
  • Greg Knaddison (greggles) (coordinator)
  • Lee Rowlands (larowlan) (coordinator)
  • Dave Long (longwave) (coordinator)
  • Drew Webber (mcdruid) (coordinator)
  • James Gilliland (neclimdul) (coordinator)
  • Juraj Nemec (poker10) (coordinator)
  • Jess (xjm) (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-55807
United States56,478 websites



Germany16,585 websites
France13,599 websites
Russia11,735 websites
Belgium7,368 websites
GB6,445 websites
Italy5,566 websites
Netherlands5,159 websites
Spain4,600 websites
Canada4,585 websites

Website Distribution by TLD

Number of websites using CVE-2026-55807
.com46,605 websites
.org16,863 websites
.de10,375 websites
.ru9,428 websites
.edu8,005 websites
.fr7,178 websites
.be6,877 websites
.nl4,423 websites
.it4,207 websites
.net3,884 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-55807

Top websites that are affected by CVE-2026-55807. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.**.uk GB***
***.gov United States***
****.fr France***
***.gov United States***
***.gov United States*,***
*******.gov United States*,***
********.***.gov United States*,***
***.gov United States*,***
******.com United States*,***
***.*******.edu United States*,***
See full domain list

FAQ

CVE-2026-55807 is Server-Side Request Forgery (SSRF) in Drupal
A total of 180,897 websites have been identified as vulnerable to CVE-2026-55807, based on global website indexing conducted by WebTechSurvey.
The Drupal is affected by the CVE-2026-55807 vulnerability.
Drupal versions up to 11.3.12 are vulnerable to CVE-2026-55807.
CVE-2026-55807 is resolved in version 11.3.12 of Drupal.