This is a security release of the Drupal 10 series.

This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:

No other fixes are included.

Which release do I choose? Security coverage information

Important update information

As part of the protection against a potential vulnerability, additional checks have been added to some of Drupal core's database related code. If you use a third-party database driver that makes use of the Drupal\Core\Database\StatementPrefetchclass, you may need to allow-list the driver by adding it to settings.php.

Drupal Core's own database drivers (and the contrib sqlsrv driver) do not require additional configuration. The contrib Oracle driver is allow-listed by default.

Example for settings.php:


$settings['database_statement_prefetch_valid_db_drivers'] = ['mydbdriver'];

VCS Label
10.2.11
Release type
Short description
Drupal 10.2.x will receive security coverage until December 2024 when Drupal 10.4.0 is released.
Packaged Git sha1
2570b33d6e36d5835119b683af0d6a866593276b
Release files
2b1d5b43e6371381093a1bfe06acde93
Release file SHA-1 hash
57d0fd609eef43139916b807a3fee7fd6f7c693d
Release file SHA-256 hash
788e545003b321deedc0df01a99ee5e7b26ed3b6e7350b2c03553dd52d2ab01b
8eb8f0a4f55730f8ab6926db1d03b3b7
Release file SHA-1 hash
d8cff3767bed7f5975905123b7fc94c82dc1f35b
Release file SHA-256 hash
ee18fb4d3552104e037d63b98d1a4fda83f47e14b9ec107519b7e1a6eee672d2