Drupal Release Notes
51 release notes curated from 1 source by the Releasebot Team. Last updated: Jul 16, 2026
- Jul 15, 2026
- Date parsed from source:Jul 15, 2026
- First seen by Releasebot:Jul 16, 2026
drupal 10.6.13
Drupal ships a security release for the Drupal 10 series, fixing moderately critical information disclosure and cross-site scripting vulnerabilities and urging sites to update immediately. No other fixes are included.
This is a security release of the Drupal 10 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
No other fixes are included.
Which release do I choose? Security coverage information
Sites on Drupal 10.6.x or below should update immediately to Drupal 10.6.13. Drupal 10.6.x will receive security coverage until Drupal 10 is end-of-life in December 2026.
Sites on Drupal 11.4.x should update immediately to Drupal 11.4.4.
Sites on Drupal 11.3.x or below should update immediately to Drupal 11.3.14.
Drupal 11.2.x and below as well as Drupal 10.5.x and below are end-of-life and do not receive security coverage.
Release type
Security update
Original source - Jul 15, 2026
- Date parsed from source:Jul 15, 2026
- First seen by Releasebot:Jul 16, 2026
drupal 11.3.14
Drupal releases a security update for the Drupal 11 series, fixing moderately critical information disclosure and cross-site scripting vulnerabilities and urging sites to update immediately. No other fixes are included.
This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012
No other fixes are included.
Which release do I choose? Security coverage information
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.14. Drupal 11.3.x will receive security coverage until December 2026 when Drupal 11.5.0 is released.
Sites on Drupal 11.4.x should update immediately to Drupal 11.4.4.
Sites on Drupal 10.6.x or below should update immediately to Drupal 10.6.13.
Drupal 11.2.x and below as well as Drupal 10.5.x and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source All of your release notes in one feed
Join Releasebot and get updates from Drupal and hundreds of other software products.
- Jul 15, 2026
- Date parsed from source:Jul 15, 2026
- First seen by Releasebot:Jul 16, 2026
drupal 11.4.4
Drupal releases a security update for the Drupal 11 series that fixes moderately critical information disclosure and cross-site scripting vulnerabilities, with no other fixes included. Sites are urged to update immediately to the recommended supported versions.
This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Moderately critical - Information disclosure - SA-CORE-2026-010
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011
Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012No other fixes are included.
Which release do I choose? Security coverage information
Sites on Drupal 11.4.x should update immediately to Drupal 11.4.4. Drupal 11.4.x will receive security coverage until June 2027 when Drupal 11.6.0 is released.
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.14.
Sites on Drupal 10.6.x should update immediately to Drupal 10.6.13.
Drupal 11.2.x and below as well as Drupal 10.5.x and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source - Jul 14, 2026
- Date parsed from source:Jul 14, 2026
- First seen by Releasebot:Jul 15, 2026
drupal 11.4.3
Drupal releases a patch bugfix update for Drupal 11, ready for production sites. It fixes multiple regressions and stability issues across routing, translation, entity queries, workspaces, and services, while continuing security coverage through June 2027.
This is a patch (bugfix) release of Drupal 11 and is ready for use on production sites. Learn more about the latest version of Drupal.
Drupal 11.4.x will receive security coverage until June 2027.
All changes since 11.4.2
- fix: #3603333 Errors when stream wrappers instantiate services in constructors because register() is called before container is built
- fix: #3152267 Invalid use of array union operator
- fix: #3608776 [regression] Route discovery isn't fully compatible with Symfony routes
- fix: #3592946 ComponentNegotiator::negotiate() re-runs on every call when no replacement is found
- fix: #3575821 locale.check_translation route is not protected against CSRF
- fix: #3593233 Cloning an aggregate entity query shares its aggregate conditions with the original
- fix: #3590350 WorkspacePublisher doesn't roll back when a PHP Error is thrown during publishing
- fix: #3593939 AttributeRouteDiscovery: invokable controllers with class-only #[Route] never register routes due to wrong condition
Release type
Bug fixes
Original source - Jul 10, 2026
- Date parsed from source:Jul 10, 2026
- First seen by Releasebot:Jul 10, 2026
drupal 11.4.2
Drupal ships a production-ready patch release for Drupal 11 that fixes update-path regressions from 11.3.x and 10.6.x to 11.4.x, resolves composer scaffolding issues, and smooths updates for sites using search and help modules with broader bug fixes and compatibility improvements.
This is a patch (bugfix) release of Drupal 11 and is ready for use on production sites. Learn more about the latest version of Drupal.
Drupal 11.4.x will receive security coverage until June 2027.
This release fixes two regressions in the update path from 11.3.x or 10.6.x to 11.4.x.
When running composer update, Drupal's scaffolding command would fail to create the newly required autoload_runtime.php in some cases, requiring running composer install in addition. This issue should now be resolved.
Sites with search and/or help modules installed would in some cases run into a fatal error during updates to enable the new search_node and search_help modules, these updates should now run smoothly.
Known issues
11.4.0 introduced an unintentional incompatibility with certain route definitions, this is being worked on in #3608776: Regression: Route discovery isn't fully compatible with Symfony routes
Several other other bugfixes and compatibility improvements are also included, see the full list below.
All changes since 11.4.1
- refactor: #3608912 Move search updates back to search module and fix missing plugin errors
- fix: #3608288 Update FileReferenceResolver::__construct() to use the more generic CacheBackendInterface
- fix: #3605792 SQL injection via unvalidated operator in case-insensitive entity query array conditions
- fix: #3608805 [random test failure] Drupal\Tests\config\Functional\ConfigInstallProfileOverrideTest::testInstallProfileConfigOverwrite
- fix: #3091285 Composer scaffolding fails when permissions on default.settings.yml or default.settings.php is not writable.
- fix: #3607866 Scaffold plugin does not always create autoload_runtime.php when upgrading to 11.4
- fix: #3609363 Regression: install_import_translations() no longer lets contrib/custom translations override core on install-from-config
- fix: #3609124 Add proper BC for ImageFormatter
- fix: #3132725 "Limit list to selected items" on exposed filters does not filter
- fix: #3609087 \Drupal\locale\LocaleProjectRepository::buildProjects() does not respect weight in 11.4.x
- task: #3608738 Avoid adding user:0 cache tag in UserRoles cache context
- fix: #3609020 BC layer in locale_translation_get_projects() implemented incorrectly
- fix: #3605554 Translations are never loaded or downloaded for a custom profile
- fix: #3608374 Data for non-revisionable/non-translatable/no-dedicated-field-tables entity types such as file is loaded twice
- fix: #3593838 Views QueryParameter argument_default plugin doesn't apply default value if root-level parameter key is present, but nested key is missing
- task: #3608308 Composer 2.10 causing Drupal recipe unpacking tests to fail
Release type:
Bug fixes
Original source Similar to Drupal with recent updates:
- Salesforce release notes57 release notes · Latest Jul 1, 2026
- Microsoft release notes739 release notes · Latest Jul 22, 2026
- Google release notes1703 release notes · Latest Jul 22, 2026
- Hubspot release notes160 release notes · Latest Jul 17, 2026
- Slack release notes179 release notes · Latest Jul 1, 2026
- 1Password release notes198 release notes · Latest Jul 14, 2026
- Jul 3, 2026
- Date parsed from source:Jul 3, 2026
- First seen by Releasebot:Jul 3, 2026
- Modified by Releasebot:Jul 10, 2026
drupal 11.4.1
Drupal ships a patch bugfix release for Drupal 11, ready for production sites. It fixes three regressions from 11.4.0 and restores stability for load handling, deprecated recipes, and JSON:API attribute route discovery.
This is a patch (bugfix) release of Drupal 11 and is ready for use on production sites.
Learn more about the latest version of Drupal.
Drupal 11.4.x will receive security coverage until June 2027.
This release fixes three regressions discovered in 11.4.0 relative to 11.3.x.Known issues
composer update may fail to successfully re-run Drupal's scaffolding command. If this fails, checking file permissions and re-running composer update or composer install may help. This issue is being worked on in #3091285: Composer scaffolding fails when permissions on default.settings.yml or default.settings.php is not writable.
Some sites with search module enabled may experience issues with updates to enable the new search_node and search_help modules. Uninstalling search module prior to updating then re-enabling the module after update (along with search_node and/or search_help) should allow other updates to complete successfully. This is being worked on in #3608912: Move search updates back to search module and fix missing plugin errors.
All changes since 11.4.0
- fix: #3607938 Chunking of Op in loadFromDedicatedTables causes Cartesian multiplication
- fix: #3608069 Restore (but don't apply) deprecated recipes to 11.4.x
- fix: #3600697 Attribute route discovery does not handle arrays for JSON:API contrib modules
Release type:
Bug fixes
Original source - Jul 1, 2026
- Date parsed from source:Jul 1, 2026
- First seen by Releasebot:Jul 3, 2026
drupal 11.4.0
Drupal ships a production-ready minor release with improvements and new functionality for Drupal 11, including new editor permissions, faster recipe installs, Brotli-compressed assets, and updated dependencies. It keeps public APIs backward compatible.
This is a a feature minor release of Drupal 11 and is ready for use on production sites. Learn more about Drupal 11 and the Drupal core release cycle.
Read the Drupal 11.4.0 release announcement for improvements and highlights in this release.
This minor release provides improvements and new functionality. It does not break backward compatibility (BC) for public APIs. There may be changes in internal APIs and experimental modules. If so, contributed and custom modules and themes may need updating. This is according to Drupal core's backward compatibility and experimental module policies.
This release may include string changes and additions. Translators can review the latest translation status on localize.drupal.org.
Drupal 11.4.x contains new features, and should be the target for new site development. Drupal 11.4.x will receive security support until June 2027.
Drupal 11.3.x will continue to receive security support until December 2026.
Drupal 11 will be supported until the release of Drupal 13.
Important update information
Upgrading from Drupal 6 and 7
Drupal 6 and 7 users can continue to migrate to Drupal 11. The migration paths from Drupal 6 and Drupal 7 to Drupal 11 will remain supported throughout Drupal 11's release cycle.
The Article and Page content types have been removed from the Standard install profile and recipe. New sites using the Standard profile or recipe must configure the content type needed.
Changes to site-owner-managed files
The robots.txt file now blocks search result pages with query parameters from being crawled by search engines. This caused search engines to index dynamically generated search results and crawl infinite combinations of faceted search pages, degrading site performance and SEO quality.
Site owners who have customized their robots.txt file should add the following rules to their robots.txt file.
Disallow: /search?
Disallow: /index.php/search?
API and behavior changes
The performance of the Drupal recipe system is improved by installing extensions in batches. Developers should use RecipeRunner::installModules(), which leverages this multi-module processing.
Drupal now generates Brotli-compressed versions of aggregated CSS and JS assets when the brotli PHP extension is installed.
A new "view unpublished block content" permission allows editors to view unpublished blocks. The "administer block content" or "access block library" permissions may no longer be needed for certain editor roles.
The Symfony Runtime component has been adopted in order to simplify the Drupal bootstrap process. Sites with custom front controller scripts should read the change record to see how they need to update their code. Existing front controllers will continue to work until at least Drupal 12.
The drupal/legacy-project template included in Drupal core is now marked abandoned. Use drupal/recommended-project instead.
Deprecated extensions
The following core modules are deprecated and will be moved to contributed projects.
Contact
Field Layout
History
Migrate Drupal
Migrate Drupal UI
Telephone
The following core theme is deprecated and will be moved to a contributed project.
Stable 9
Sites will receive warning messages when deprecated extensions are in use. Review the deprecated extension documentation on the steps to take if your site uses any of these modules.
Additional modules may be deprecated prior to Drupal 12.
PHP dependency changes
The drupal/core-recommended metapackage, which restricts versions of Drupal's upstream dependencies to versions those that have been fully tested, will no longer pin versions of Guzzle, Twig, or Symfony polyfills, so that security and other updates can be applied to sites without requiring a new Drupal core release.
The twig/html-extra package, which exposes the html_cva, html_attr, and html_classes functions has been added. All three are now available for use in Twig templates
Many dependencies have received minor- and patch-level updates to the latest versions.
Frontend (CSS and JavaScript) production dependency changes
CKEditor is updated to CKEditor 5 47.6.2.
Many dependencies have received minor- and patch-level updates to the latest versions.
Known issues
Search the issue queue for known issues.
All changes since Drupal 11.4.0-rc2
task: #3606377 Update eslint and stylelint to latest minors
fix: #3387100 Missing config schema for core.base_field_override...* third_party_settings.content_translation
task: #3606390 Update JavaScript dependencies but not linting
task: #3600644 Pull up attributes from block plugins if the render array has no type or theme on the top level
build: #3600889 Remove some minor constraints from core-recommended
fix: #3606969 Content translation column group settings only show up once there are base field overrides saved
task: #3606709 Remove superflous property from update MailHandler
fix: #3072557 Plugin ID menu_link_content was not found in _menu_link_content_update_path_alias() when does not yet exist
task: #3592037 Settings::get() should not trigger a deprecation for settings with no replacement when the setting is not configured
task: #3599680 Consolidate, merge, and refactor Gin's CSS variable's into Admin theme's original variables.
revert: #3605262 Database write optimizations result in inconsistent data in data and revision tables
fix: #3591520 Fix format of some deprecation messages
task: #3581427 Add return types to BasicAuthResourceTestTrait
fix: #3552669 Error when fetching all query results as class instances
task: #3586760 Use composite key Upsert queries in core
Revert "chore: #3581427 Add return types to BasicAuthResourceTestTrait"
chore: #3581427 Add return types to BasicAuthResourceTestTrait
task: #3603733 Update guzzlehttp/psr7 to 2.12.1 and guzzlehttp/guzzle to 7.12.1
task: #3514748 (11.x revert) Remove legacy browser support from js.module.css
fix: #3585723 #date_year_range does not support years < 1000
task: #3590536 Add a MAINTAINERS.txt entry for Drupal CLI with Moshe and dww as co-maintainers
task: #3594426 Use local variable over object in \Drupal\Core\Entity\Sql\SqlContentEntityStorage::loadFromDedicatedTables() for column names
fix: #3597406 [regression] DrupalApplication (for 'dr') needs to support DRUPAL_DEV_SITE_PATH env var
fix: #3601433 Fix local_status deprecation by clearing source in a post update
fix: #3599189 Some deprecation messages are missing E_USER_DEPRECATED
Back to dev.
Merged 11.4.0-rc2.
Merged 11.4.0-rc2.
Release type:
Bug fixes
New features
Original source - Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jun 23, 2026
drupal 10.6.12
Drupal ships a bugfix release for Drupal 10 that is ready for production use and fixes Composer security errors when installing drupal/core-recommended. It also includes updates and fixes for media preview, Claro tabledrag styles, and other reported issues.
This is a patch (bugfix) release of Drupal 10 and is ready for use on production sites. Learn more about the latest version of Drupal.
This update solves Composer security errors from third party components when installing drupal/core-recommended.
Drupal 10.6.x will receive security support until December 2026. Drupal 10.5.x will continue to receive security support until June 2026.
All changes since 10.6.11
- task: #3603733 Update guzzlehttp/psr7 to 2.12.1 and guzzlehttp/guzzle to 7.12.1
- Merged 10.6.11.
- fix: #3599842 guzzlehttp/psr7 needs to be updated to >2.10.2 to fix 2 security issues
- Revert "fix: #3593390 Media Preview Endpoint Leaks Labels Of Non-Viewable Media By UUID"
- fix: #3593390 Media Preview Endpoint Leaks Labels Of Non-Viewable Media By UUID
- docs: #3590805 DiscoveryCachedTrait::$definitions @var docblock should be array|null to match runtime semantics
- fix: #3578398 Tabledrag styles in claro break expandable elements (Firefox)
- Back to dev.
Release type:
- Bug fixes
- Jun 23, 2026
- Date parsed from source:Jun 23, 2026
- First seen by Releasebot:Jun 23, 2026
drupal 11.3.13
Drupal releases a Drupal 11 patch update that is ready for production sites and fixes Composer security errors in drupal/core-recommended, with dependency updates and bug fixes included.
This is a patch (bugfix) release of Drupal 11 and is ready for use on production sites. Learn more about the latest version of Drupal.
This update solves Composer security errors from third party components when installing drupal/core-recommended.
Drupal 11.3.x will receive security coverage until December 2026.
All changes since 11.3.12
- task: #3603733 Update guzzlehttp/psr7 to 2.12.1 and guzzlehttp/guzzle to 7.12.1
- Merged 11.3.12.
- fix: #3599842 guzzlehttp/psr7 needs to be updated to >2.10.2 to fix 2 security issues
- fix: #3584277 [random test failure] ComposerRequirementTest::testComposerInfoShown
- Back to dev.
Release type:
Bug fixes
Original source - Jun 17, 2026
- Date parsed from source:Jun 17, 2026
- First seen by Releasebot:Jun 18, 2026
drupal 11.4.0-rc2
Drupal ships a Drupal 11 release candidate that focuses on security fixes, dependency updates, and several regressions and deprecations. It also includes an oEmbed trusted host pattern change for some sites and other core fixes ahead of the next stable feature release.
This is a release candidate for the next minor version (feature release) of Drupal 11. Release candidates are not supported for production sites, but they are intended for widespread testing in preparation for the upcoming stable release. More information on release candidates.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
- Drupal core - Critical - PHP object injection - SA-CORE-2026-005
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
- Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
- Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
- Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Important update information
This release also updates dependencies for upstream security releases:
guzzlehttp/psr7 is updated to 2.11.0 for a guzzlehttp/psr7 security fix.
Sites using URL discovery for Media oEmbed providers must add an additional media_oembed_discovery_trusted_host_patterns entry to settings.php for their list of known oEmbed providers (like YouTube and Vimeo). It is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com. $settings['media_oembed_discovery_trusted_host_patterns'] = [ '^example\.com$', ];Most sites likely use providers.json to define their known oEmbed providers instead, and do not require this change.
Other changes since Drupal 11.4.0-rc1
- task: #3587564 Move search functionality from node to Search module
- fix: #3400181 [regression] calling TypedConfigManager::getDefinition() causes cache pollution
- fix: #3600694 locale_translate_file_attach_properties() BC layer incorrectly always sets override langcode to undefined
- fix: #3590050 Deprecate and replace locale_status related functions
- task: #3585891 Deprecate Validating CSRF tokens with the 'rest' key in CsrfRequestHeaderAccessCheck
- fix: #3597692 [regression] The 'dr' command doesn't set DRUPAL_TEST_IN_CHILD_SITE
- Revert "task: #3590050 Deprecate and replace locale_status related functions"
Release type:
Security update
Original source - Jun 17, 2026
- Date parsed from source:Jun 17, 2026
- First seen by Releasebot:Jun 18, 2026
drupal 10.5.12
Drupal releases a security update for the Drupal 10 series that fixes multiple critical and moderately critical vulnerabilities, including PHP object injection, gadget chain, cache poisoning, open redirect, server-side request forgery, and improper validation, and updates guzzlehttp/psr7 for an upstream security fix.
This is a security release of the Drupal 10 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Important update information
This release also updates dependencies for upstream security releases:
guzzlehttp/psr7 is updated to 2.10.4 for a guzzlehttp/psr7 security fix.
Sites using URL discovery for Media oEmbed providers must add an additional media_oembed_discovery_trusted_host_patterns entry to settings.php for their list of known oEmbed providers (like YouTube and Vimeo). It is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com. $settings['media_oembed_discovery_trusted_host_patterns'] = [ '^example\.com$', ];Most sites likely use providers.json to define their known oEmbed providers instead, and do not require this change.
Which release do I choose? Security coverage information
This is likely the final release for 10.5.x. 11.5.x is expected to be end-of-life next week. Sites on Drupal 10.5.x should update immediately to Drupal 10.5.12, and then update to Drupal 10.6 or higher as soon as possible.
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.12.
Sites on Drupal 11.2.x should update immediately to Drupal 11.2.14.
Sites on Drupal 10.6.x should update immediately to Drupal 10.6.11.
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source - Jun 17, 2026
- Date parsed from source:Jun 17, 2026
- First seen by Releasebot:Jun 18, 2026
drupal 11.2.14
Drupal releases a security update for the 11 series that fixes multiple critical and moderately critical vulnerabilities, updates a dependency for a security fix, and adds guidance for sites using Media oEmbed URL discovery.
This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
- Drupal core - Critical - PHP object injection - SA-CORE-2026-005
- Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
- Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
- Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
- Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Important update information
This release also updates dependencies for upstream security releases:
guzzlehttp/psr7 is updated to 2.10.4 for a guzzlehttp/psr7 security fix.
Sites using URL discovery for Media oEmbed providers must add an additional media_oembed_discovery_trusted_host_patterns entry to settings.php for their list of known oEmbed providers (like YouTube and Vimeo). It is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com. $settings['media_oembed_discovery_trusted_host_patterns'] = [ '^example\.com$', ];Most sites likely use providers.json to define their known oEmbed providers instead, and do not require this change.
Which release do I choose? Security coverage information
This is likely the final release for 11.2.x. 11.2.x is expected to be end-of-life next week. Sites on Drupal 11.2.x should update immediately to Drupal 11.2.14, and then plan to update to Drupal 11.3 or higher as soon as possible.
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.12.
Sites on Drupal 10.6.x should update immediately to Drupal 10.6.11.
Sites on Drupal 10.5.x should update immediately to Drupal 10.5.12.
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source - Jun 17, 2026
- Date parsed from source:Jun 17, 2026
- First seen by Releasebot:Jun 18, 2026
drupal 10.6.11
Drupal releases a security update for Drupal 10 that fixes multiple critical and moderately critical vulnerabilities, updates dependencies, and adds guidance for Media oEmbed trusted host patterns. Sites are urged to update immediately.
This is a security release of the Drupal 10 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Important update information
This release also updates dependencies for upstream security releases:
guzzlehttp/psr7 is updated to 2.10.4 for a guzzlehttp/psr7 security fix.
Sites using URL discovery for Media oEmbed providers must add an additional media_oembed_discovery_trusted_host_patterns entry to settings.php for their list of known oEmbed providers (like YouTube and Vimeo). It is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com. $settings['media_oembed_discovery_trusted_host_patterns'] = [ '^example\.com$', ];Most sites likely use providers.json to define their known oEmbed providers instead, and do not require this change.
Which release do I choose? Security coverage information
Sites on Drupal 10.6.x should update immediately to Drupal 10.6.11. Drupal 10.6.x will receive security coverage until December 2026.
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.12.
Sites on Drupal 11.2.x should update immediately to Drupal 11.2.14.
Sites on Drupal 10.5.x should update immediately to Drupal 10.5.12.
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source - Jun 17, 2026
- Date parsed from source:Jun 17, 2026
- First seen by Releasebot:Jun 18, 2026
drupal 11.3.12
Drupal releases a security update for the Drupal 11 series, fixing critical and moderately critical vulnerabilities, updating dependencies, and adding guidance for Media oEmbed trusted host settings. Sites are urged to update immediately.
This is a security release of the Drupal 11 series.
This release fixes security vulnerabilities. Sites are urged to update immediately after reading the notes below and the security announcements:
Drupal core - Critical - PHP object injection - SA-CORE-2026-005
Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006
Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007
Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008
Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009
Important update information
This release also updates dependencies for upstream security releases:
guzzlehttp/psr7 is updated to 2.10.4 for a guzzlehttp/psr7 security fix.
Sites using URL discovery for Media oEmbed providers must add an additional media_oembed_discovery_trusted_host_patterns entry to settings.php for their list of known oEmbed providers (like YouTube and Vimeo). It is an array containing a series of regular expressions for matching host names for discovery. It follows the same pattern as the existing trusted hosts settings.
Example:
// Only allow URL discovery from example.com. $settings['media_oembed_discovery_trusted_host_patterns'] = [ '^example\.com$', ];Most sites likely use providers.json to define their known oEmbed providers instead, and do not require this change.
Which release do I choose? Security coverage information
Sites on Drupal 11.3.x should update immediately to Drupal 11.3.12. Drupal 11.3.x will receive security coverage until December 2026 when Drupal 11.5.0 is released.
Sites on Drupal 11.2.x should update immediately to Drupal 11.2.14.
Sites on Drupal 10.6.x should update immediately to Drupal 10.6.11.
Sites on Drupal 10.5.x should update immediately to Drupal 10.5.12.
Drupal 11.1.x, Drupal 11.0.x, Drupal 10.4.x, and below are end-of-life and do not receive security coverage.
Release type:
Security update
Original source - Jun 11, 2026
- Date parsed from source:Jun 11, 2026
- First seen by Releasebot:Jun 11, 2026
drupal 11.4.0-rc1
Drupal releases a Drupal 11.4 release candidate with new features, improvements, and backward-compatible updates for wider testing ahead of the stable minor release. It also removes Article and Page from the Standard install profile and recipe for new sites.
This is a release candidate for the next minor version (feature release) of Drupal 11. Release candidates are not supported for production sites, but they are intended for widespread testing in preparation for the upcoming stable release. More information on release candidates.
This minor release provides improvements and new functionality. It does not break backward compatibility (BC) for public APIs. There may be changes in internal APIs and experimental modules. If so, contributed and custom modules and themes may need updating. This is according to Drupal core's backward compatibility and experimental module policies.
This release may include string changes and additions. Translators can review the latest translation status on localize.drupal.org.
Drupal 11.4.x contains new features, and should be the target for new site development. Drupal 11.4.x will receive security support until June 2027.
Drupal 11.3.x will continue to receive security support until December 2026.
Drupal 11 will be supported until the release of Drupal 13.
Important update information
The Article and Page content types have been removed from the Standard install profile and recipe. New sites using the Standard profile or recipe must configure the content type needed.
Search the issue queue for known issues.
All changes since Drupal 11.4.0-beta1
- fix: #3593963 Field loading can hit the MySQL 61 table join limit if there are ~60 fields
- fix: #3590897 Sidebar toggle is visible and functioning in media library dialog, but shouldn't be there
- fix: #3592497 Buttons are not rendered on the bottom of the page for Node create/edit for
- task: #3590364 Part 2 of Consolidate, refactor, remove and untangle Claro's CSS from Default Admin theme
- task: #3590050 Deprecate and replace locale_status related functions
- fix: #3593390 Media Preview Endpoint Leaks Labels Of Non-Viewable Media By UUID
- task: #3594241 Remove reference of telephone from help topics
- task: #3522220 Add tests for SA-CORE-2025-003
- fix: #3593223 [PHP 8.5] OptionsWidgetBase::getSelectedOptions tries to access null array key in some scenarios
- task: #3593777 Add tests for SA-CORE-2025-001
- task: #3594057 Remove/replace any tests using telephone
- feat: #3453474 CLI entry point in Drupal Core
- fix: #3132725 Limit list to selected items on exposed filters does not filter
- fix: #3594092 loadUnchanged() returns an in-memory-modified entity when hook_entity_preload() swaps in a non-default revision
- fix: #3592577 Ensure that hook attributes are never parsed from a stale opcache
- task: #3581056 (follow-up) Introduce a OneTimeAuthentication service and deprecate user_pass_rehash
- task: #3581056 Introduce a OneTimeAuthentication service and deprecate user_pass_rehash
- task: #3588490 Don't reset the extension lists in system requirements
- task: #3588276 Remove comment module dependency from standard profile and recipe
- fix: #3592878 ContextualLinksHelper::addLinks() assertion rejects the 'exposed_filter' location, fataling ViewsExposedFilterBlock
- feat: #3591076 JS translation files should be generated and served from assets://
- task: #2983639 Re-enable a bit of test coverage for Workspaces
- fix: #3041170 RowPluginBase::render() update docblock and trigger deprecation for old typehint
- perf: #3593202 Drop the explicit clear of plugin caches in drupal_flush_all_caches()
- docs: #3590805 DiscoveryCachedTrait::$definitions @var docblock should be array|null to match runtime semantics
- test: #3577840 Consolidate test methods in GenerateThemeTest
- docs: #3549362 Wrong return type in UserPermissionsForm::permissionsByProvider()
- feat: #3020938 Add view unpublished block content permission
- fix: #3578398 Tabledrag styles in claro break expandable elements (Firefox)
- task: #3486503 Add a file parsing cache collector to replace some uses of FileCache
Back to dev.
Release type:
New features
Original source
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.