CVE-2019-10910: Drupal

Critical severity, CVSS 9.8. EPSS: 6% chance of exploitation in the next 30 days.

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

Affected products

  • Drupal Drupal: from 8.5.0, before 8.5.15 (fixed in 8.5.15); from 8.6.0, before 8.6.15 (fixed in 8.6.15)
  • Sensiolabs Symfony: from 2.7.0, before 2.7.51 (fixed in 2.7.51); from 2.8.0, before 2.8.50 (fixed in 2.8.50); from 3.4.0, before 3.4.26 (fixed in 3.4.26); from 4.1.0, before 4.1.12 (fixed in 4.1.12); from 4.2.0, before 4.2.7 (fixed in 4.2.7)

Published 2019-05-16. Last modified 2026-06-17.