DRUPAL-CONTRIB-2026-105

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/captcha_protected_page/DRUPAL-CONTRIB-2026-105.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-105
Aliases
  • CVE-2026-81168
Published
2026-08-26T17:34:35Z
Modified
2026-08-26T22:30:03.828693828Z
Summary
[none]
Details

This module enables site administrators to require CAPTCHA confirmation on specific pages.

The module does not sufficiently validate its CAPTCHA verification cookies. Under certain circumstances, an unauthenticated user or automated bot can forge the cookie and bypass CAPTCHA verification entirely.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/captcha_protected_page

Package

Name
drupal/captcha_protected_page
Purl
pkg:composer/drupal/captcha_protected_page?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2
Database specific
Show details
{
    "constraint": "<1.0.2"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/captcha_protected_page/DRUPAL-CONTRIB-2026-105.json"
affected_versions
"<1.0.2"