{"id":"DRUPAL-CONTRIB-2026-188","details":"This module enables you to combine multiple image styles into a single image derivative.\n\nThe module does not sufficiently validate image style names when generating image derivatives. Under certain circumstances, this allows anonymous users to generate image derivatives without a valid token, potentially leading to a denial of service.\n\nSites are affected simply by having the module installed, even when no combined image styles are configured or in use.\n\nThis vulnerability is mitigated by the fact that only public files can be targeted, and derivatives of private files are still protected by core's token check.","aliases":["CVE-2026-96377"],"modified":"2026-09-23T19:15:05.628812443Z","published":"2026-09-23T17:21:51Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-188"}],"affected":[{"package":{"name":"drupal/combined_image_style","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/combined_image_style?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.7"}],"database_specific":{"constraint":"\u003c1.0.7"}}],"database_specific":{"affected_versions":"\u003c1.0.7","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/combined_image_style/DRUPAL-CONTRIB-2026-188.json"}}],"schema_version":"1.9.0","credits":[{"name":"Sven Decabooter (svendecabooter)","contact":["https://www.drupal.org/u/svendecabooter"]}]}