This is a security release of the Drupal 10 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
- Drupal core - Moderately critical - Denial of Service - SA-CORE-2025-005
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-006
- Drupal core - Moderately critical - Defacement - SA-CORE-2025-007
- Drupal core - Moderately critical - Information disclosure - SA-CORE-2025-008
Important update information
-
SA-CORE-2025-005 removes a feature of an underlying library where request attributes can be manipulated. It is possible that some sites are actually relying on this feature. In this case, the behavior can be replicated by implementing a custom stack middleware to alter the incoming request.
-
This release updates minimum versions of Symfony Framework libraries. The updated libraries include a fix for CVE-2025-64500. Drupal does not expose this vulnerability, but the update is included as a hardening for other applications that may extend the library directly.
No other fixes are included.
Which release do I choose? Security coverage information
- Drupal 10.5.x will receive security coverage until June 2026.
- Sites on Drupal 11.2.x should update immediately to Drupal 11.2.8.
- Sites on Drupal 11.1.x should update immediately to Drupal 11.1.9.
- Sites on Drupal 10.4.x should update immediately to Drupal 10.4.9.
- Drupal 11.0.x, Drupal 10.3.x, and below are end-of-life and do not receive security coverage.