Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 06 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bmeme
Bmeme http Client Manager |
|
| CPEs | cpe:2.3:a:bmeme:http_client_manager:*:*:*:*:*:drupal:*:* cpe:2.3:a:bmeme:http_client_manager:11.0.0:*:*:*:*:drupal:*:* |
|
| Vendors & Products |
Bmeme
Bmeme http Client Manager |
Thu, 29 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Drupal
Drupal http Client Manager |
|
| Vendors & Products |
Drupal
Drupal http Client Manager |
Wed, 28 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1. |
| Title | drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation | HTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126 |
| Weaknesses | CWE-754 |
Fri, 19 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation | |
| Weaknesses | CWE-653 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-01-29T16:30:13.234Z
Reserved: 2025-12-17T17:37:30.402Z
Link: CVE-2025-14840
Updated: 2026-01-29T16:27:57.847Z
Status : Analyzed
Published: 2026-01-28T20:16:08.623
Modified: 2026-02-06T18:48:00.103
Link: CVE-2025-14840
OpenCVE Enrichment
Updated: 2026-01-29T09:08:25Z