This is a security release of the Drupal 10 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
- Drupal core - Critical - Cross-Site Scripting - SA-CORE-2025-001
- Drupal core - Moderately critical - Access Bypass - SA-CORE-2025-002
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-003
No other fixes are included.
Which release do I choose? Security coverage information
- Drupal 10.4.x will receive security coverage until December 2025 when Drupal 10.6.0 is released.
- Sites on Drupal 10.3.x should update immediately to Drupal 10.3.11.
- Drupal 10.2.x and below are end-of-life and do not receive security coverage.
Important update information
Users now need the “Administer content” permission (administer nodes) to perform certain bulk operations. Alternatively, sites can install the Granular Node Permissions module and grant more specific permissions.
VCS Label
10.4.3
Release type
Short description
Actively maintained with bugfixes and forwards compatibility backports every six months. Use this version if you already have a Drupal 10 site, until you're ready to update to 11.x.
Packaged Git sha1
1d937cf1b3dc72cc871440008434ec4f81ba0969
Release files
f1650f9ae2f56900f24c15efd7e0c81e
Release file SHA-1 hash
885d8875d809317f41a637d7313893c1355f019e
Release file SHA-256 hash
3ca6d6ebaa5d46818d77cecc326d55fb2e68c558f490f00365414acfc5b25ef5
6b34f4a3e786534567e09d0057af51e3
Release file SHA-1 hash
301405742a95afaaab30b6e907710ee4798d0b7e
Release file SHA-256 hash
91262fd071420d8dfa809d5f02da0de683664d7538ec2995be5a26c702466c8c