CVE-2016-9450: Drupal
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
Affected products
- Drupal Drupal: version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.0.3 only; version 8.0.4 only; version 8.0.5 only; …
Published 2016-11-25. Last modified 2026-06-17.