DRUPAL-CONTRIB-2026-188

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/combined_image_style/DRUPAL-CONTRIB-2026-188.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-188
Aliases
  • CVE-2026-96377
Published
2026-09-23T17:21:51Z
Modified
2026-09-23T19:15:05Z
Summary
[none]
Details

This module enables you to combine multiple image styles into a single image derivative.

The module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.

Sites are affected simply by having the module installed, even when no combined image styles are configured or in use.

This vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/combined_image_style

Package

Name
drupal/combined_image_style
Purl
pkg:composer/drupal/combined_image_style?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.7
Database specific
Show details
{
    "constraint":  "<1.0.7"
}

Database specific

affected_versions
"<1.0.7"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/combined_image_style/DRUPAL-CONTRIB-2026-188.json"