This is a security release of the Drupal 9 series.

This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcement:

No other fixes are included.

Which release do I choose? Security coverage information

  • Drupal 9.2.x will receive security coverage until June 15, 2022 when Drupal 9.4.0 is released. Update to Drupal 9.3.x soon to continue receiving security coverage.
  • Versions of Drupal 9 prior to 9.2.x are end-of-life and do not receive security coverage.
  • Versions of Drupal 8 are end-of-life and do not receive security coverage.

Important update information

  • Drupal 9.2 core now requires guzzlehttp/guzzle 6.5.7 or higher (up from 6.5.6).

  • No changes have been made to the .htaccess, web.config, robots.txt, or default settings.php files in this release, so updating custom versions of those files is not necessary if your site is already on the previous release.
VCS Label
9.2.21
Release type
Short description
Drupal 9.2.x will receive security coverage until June 2022 when Drupal 9.4.0 is released.
Packaged Git sha1
3428eb70b1bdc73e804a7c8888002e95a26f9bdd
Release files
2c3a845b8d166b647847eb86b6329dfc
Release file SHA-1 hash
16ffd854cb97839ec98ed38de6ff26e908ef9d36
Release file SHA-256 hash
e61bedd624e1ea620375eacb99353fa738b98e2ed21ea0cf6705abbb4c59d7ea
bc3420d488052dca2c5a802827074b25
Release file SHA-1 hash
bbd22146661ce01b9e772d5e471630536d080c13
Release file SHA-256 hash
e06cdb0881a427fb0fbe1821bee251442240fa50cf2952211d1797f5a402d8e6