|
Clarify/document our policy about XSS paylods |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 month 2 weeks |
|
CVE-2026-77152 - Publish Field Collection CVE ID |
Needs work |
Normal |
Support request |
7.x-1.x-dev |
Code |
|
1 month 5 days |
|
July 2026 CVEs |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 month 1 week |
|
Shorten test embargo for security issues |
Active |
Normal |
Plan |
7.x-1.x-dev |
Documentation |
|
6 days 13 hours |
|
Publish CVE-2026-19030 for CAPTCHA failure provides login credential validation feedback |
Needs work |
Normal |
Task |
7.x-1.x-dev |
Code |
|
2 months 2 weeks |
|
[policy] Treat CAPTCHA bypasses as non-security bugs |
Active |
Normal |
Plan |
7.x-1.x-dev |
Code |
|
4 months 1 week |
|
Policy: AI tools allow "anyone" to attack sites, so lower-score vulnerabilities should still be given SAs |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
3 weeks 6 days |
|
CVE request for LDAP - CVE-2026-6908 |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
4 months 1 week |
|
Policy about issuing security advisories |
Active |
Normal |
Support request |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
3 weeks 5 days |
|
Change policy regarding timeline for resolution and disclosure of security vulnerabilities to be more strict |
Active |
Normal |
Task |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
4 years 3 months |
|
Publish CVE-2026-16132 for Icon |
Needs review |
Normal |
Support request |
7.x-1.x-dev |
Documentation |
|
1 month 3 weeks |
|
Publish CVE-2026-16136 for Views Reference Filter (enttityreference_filter) |
Needs work |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 month 3 weeks |
|
Create script to pull advisory data to csv files |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 month 1 week |
|
Expand the ability of module maintainers to mark a particular release as security. |
Active |
Major |
Task |
7.x-1.x-dev |
Code |
|
2 years 1 month |
|
Document the labels on security issues in Drupalcode |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
2 months 6 days |
|
Unsuported Modules: Establish timeline for publishing of vulnerability info to allow for possible CVE creation |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
1 year 8 months |
|
Switch to CVSS scoring |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
2 years 4 months |
|
OpenID Connect: Request update to CVE-2026-3530 |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
3 months 1 day |
|
OpenID Connect: Request update to CVE-2026-3531 |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
3 months 1 day |
|
OpenID Connect: Request update to CVE-2026-3532 |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
3 months 1 day |
|
CAPTCHA: Request update to CVE-2026-3214 |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Code |
|
2 months 4 weeks |
|
GitLab security issue template should ask for impacted version |
Active |
Normal |
Bug report |
7.x-1.x-dev |
User interface |
|
2 months 4 weeks |
|
Define standard description for marking an existing permission as "restrict access" |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
4 months 1 week |
|
Plan for how to meet 72 hour publication obligation (CNAv4.1 section 4.5.1.4) |
Active |
Normal |
Plan |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
3 months 1 week |
|
Documenting the Security/CVE process for D7ES providers |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
aangel |
1 year 1 week |
|
Review and adopt CWE assignments from NIST |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
6 months 1 week |
|
Align DST vulnerability determination criteria to CVE standards |
Active |
Critical |
Support request |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
1 year 11 months |
|
Incorrect affected versions on advisories |
Active |
Normal |
Bug report |
7.x-1.x-dev |
Miscellaneous |
|
1 year 2 weeks |
|
Create CVEs for 2016 (especially for highly critical issues) |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 3 weeks |
|
More flexible language for git vetted status for co-maintainers of existing projects |
Active |
Normal |
Plan |
7.x-1.x-dev |
Code |
|
3 years 6 months |
|
Allow filtering the All Issues view by version |
Needs review |
Normal |
Feature request |
7.x-1.x-dev |
User interface |
|
1 year 2 months |
|
Get an Open Source Security Foundation badge for Drupal (core? contrib?) |
Needs review |
Normal |
Task |
7.x-1.x-dev |
Miscellaneous |
|
4 years 6 months |
|
Clarify the Drupal Security Team Disclosure Policy |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 3 months |
|
Policy: Post CVE number / link on private issue |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Documentation |
|
1 year 3 months |
|
Run a static application security test (SAST) as part of core CI |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 4 months |
|
Create a survey for the community prior to Drupalcon |
Needs work |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 5 months |
|
issues_by_followup_date view should default to Open status |
Active |
Normal |
Bug report |
7.x-1.x-dev |
Code |
|
1 year 6 months |
|
Prohibit the ability to adopt a project |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
2 years 2 months |
|
Require in-person identity confirmation to receive "Git vetted user" role. |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Code |
|
2 years 2 months |
|
[META|POLICY] Think of a way to make adding a (co-) maintainer more trustworthy |
Active |
Major |
Task |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
1 year 7 months |
|
Develop and publish policy regarding missed SA notices |
Active |
Normal |
Task |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
4 years 5 months |
|
Improve Security Risk Levels Defined docs page |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
3 years 3 days |
|
Collect CVE related details as part of Security Issue |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 10 months |
|
Automate publishing of CVE's |
Active |
Normal |
Task |
7.x-1.x-dev |
Code |
|
1 year 10 months |
|
Update policy to explicitly state security issues will be handled privately |
Active |
Normal |
Feature request |
7.x-1.x-dev |
Security Working Group (policy questions) |
|
3 years 11 months |
|
[META] Increase Security of Project Ownership Transfer Process |
Active |
Normal |
Plan |
7.x-1.x-dev |
Code |
|
2 years 2 months |
|
Document the process for updating an "unsupported" SA due to new adoption |
Active |
Normal |
Task |
7.x-1.x-dev |
Documentation |
|
3 years 2 weeks |
|
Change SA opt-in to differentiate between "not opted in (yet)" vs "opted out" |
Active |
Normal |
Feature request |
7.x-1.x-dev |
User interface |
|
2 years 10 months |
|
Update security issue version field for semantic versioning & Drupal 9 |
Active |
Normal |
Task |
7.x-1.x-dev |
User interface |
|
5 years 10 months |
|
Create new documentation guide & pages that clearly documents what issues are not considered security issues |
Active |
Normal |
Task |
7.x-1.x-dev |
Miscellaneous |
|
4 years 6 months |