CVE-2024-11941: Drupal
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.
Affected products
- Drupal Drupal: from 8.0.0, before 10.1.8 (fixed in 10.1.8); from 10.2.0, before 10.2.2 (fixed in 10.2.2)
Published 2024-12-05. Last modified 2026-06-17.