{"id":"DRUPAL-CORE-2026-011","details":"Drupal core 11.2 and above integrate the HTMX JavaScript library.\n\nDrupal core's XSS filter does not sufficiently sanitize certain HTMX attributes, which can lead to a cross-site scripting (XSS) vulnerability.\n\nThe vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes.","aliases":["CVE-2026-15917"],"modified":"2026-07-15T20:56:45.436756Z","published":"2026-07-15T19:51:57Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-core-2026-011"}],"affected":[{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.3.0"},{"fixed":"11.3.14"}],"database_specific":{"constraint":"\u003e=11.3.0 \u003c11.3.14"}},{"type":"ECOSYSTEM","events":[{"introduced":"11.4.0"},{"fixed":"11.4.4"}],"database_specific":{"constraint":"\u003e=11.4.0 \u003c11.4.4"}},{"type":"ECOSYSTEM","events":[{"introduced":"11.2.0"},{"fixed":"11.3.0"}],"database_specific":{"constraint":"11.2.*"}}],"versions":["11.2.0","11.2.1","11.2.10","11.2.11","11.2.12","11.2.13","11.2.14","11.2.2","11.2.3","11.2.4","11.2.5","11.2.6","11.2.7","11.2.8","11.2.9","11.3.0","11.3.0-alpha1","11.3.0-beta1","11.3.0-rc1","11.3.0-rc2","11.3.1","11.3.10","11.3.11","11.3.12","11.3.13","11.3.2","11.3.3","11.3.4","11.3.5","11.3.6","11.3.7","11.3.8","11.3.9","11.4.0","11.4.1","11.4.2","11.4.3"],"database_specific":{"affected_versions":"\u003e=11.3.0 \u003c11.3.14 || \u003e=11.4.0 \u003c11.4.4 || 11.2.*","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/core/DRUPAL-CORE-2026-011.json"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}