This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
- Drupal core - Critical - Cross-Site Scripting - SA-CORE-2025-001
- Drupal core - Moderately critical - Access Bypass - SA-CORE-2025-002
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2025-003
No other fixes are included.
Which release do I choose? Security coverage information
- Drupal 11.0.x will receive security coverage until June 2025 when Drupal 11.2.0 is released and sites should plan to update to Drupal 11.1 or 11.2 by June 2025.
- Sites on Drupal 10.4.x should update immediately to Drupal 10.4.3.
- Sites on Drupal 10.3.x should update immediately to Drupal 10.3.13.
- Drupal 10.2.x and below are end-of-life and do not receive security coverage.
Important update information
Users now need the “Administer content” permission (administer nodes) to perform certain bulk operations. Alternatively, sites can install the Granular Node Permissions module and grant more specific permissions.
VCS Label
11.0.12
Release type
Short description
Drupal 11.0.x will receive security coverage until June 2025 when Drupal 11.2.0 is released.
Packaged Git sha1
5b04436371352a467c746e91c046fb59bf14e5a8
Release files
379d4404486f1e6f3e2f5a158597c25f
Release file SHA-1 hash
c153f52e1d78c962c7fd81b372caa9b2e884c859
Release file SHA-256 hash
01ce6aacfbde35ddf71deb7c81d29fde0ac781c4183541ccd3f3113a9b0791cb
7408138f23b8d93f21ae55c401efcdab
Release file SHA-1 hash
2b59c67d56301a478e1a8554592386c1db3dfad0
Release file SHA-256 hash
61155e2953a5d5e84798d6fd89fa7192a69550813ba213e7add79868d1a8d2cb