Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fg8x-q69g-4qp3 | Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables |
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2025-111 |
|
Fri, 12 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Reverse Proxy Header Project
Reverse Proxy Header Project reverse Proxy Header |
|
| CPEs | cpe:2.3:a:reverse_proxy_header_project:reverse_proxy_header:*:*:*:*:*:drupal:*:* | |
| Vendors & Products |
Reverse Proxy Header Project
Reverse Proxy Header Project reverse Proxy Header |
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal drupal Drupal reverse Proxy Header |
|
| Vendors & Products |
Drupal
Drupal drupal Drupal reverse Proxy Header |
Thu, 30 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 29 Oct 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Validation of Consistency within Input vulnerability in Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables.This issue affects Reverse Proxy Header: from 0.0.0 before 1.1.2. | |
| Title | Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111 | |
| Weaknesses | CWE-1288 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2025-10-30T13:31:48.665Z
Reserved: 2025-09-24T16:53:13.156Z
Link: CVE-2025-10929
Updated: 2025-10-30T13:31:02.737Z
Status : Analyzed
Published: 2025-10-30T00:15:34.187
Modified: 2025-12-12T17:51:52.840
Link: CVE-2025-10929
No data.
OpenCVE Enrichment
Updated: 2025-10-30T14:37:45Z
Github GHSA