A new security vulnerability, identified as CVE-2025-10929, has been discovered in the Drupal Reverse Proxy Header module. This issue involves an improper validation of consistency within input, which could allow attackers to manipulate user-controlled variables. Understanding such vulnerabilities is crucial for maintaining the security of your Drupal websites.
CVE Details
This particular security flaw affects the Drupal Reverse Proxy Header module. It was first made public on October 30, 2025. The vulnerability is currently classified with a Medium severity level and has been thoroughly analyzed by security experts.
- Product: Drupal Reverse Proxy Header module
- Published Date: October 30, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability specifically impacts the Reverse Proxy Header module for Drupal. All versions starting from 0.0.0 up to, but not including, version 1.1.2 are susceptible to this flaw. If you are running any version of the Reverse Proxy Header module older than 1.1.2, your Drupal installation is at risk.
Current Status
As of December 12, 2025, this vulnerability (CVE-2025-10929) has been fully analyzed. This means security researchers have understood its nature and potential impact. The next step for affected users is to apply available patches or mitigation strategies.
Severity Level
Rated with a CVSS score of 5.3, this vulnerability is categorized as Medium severity. A medium severity rating indicates that while the vulnerability is not critical, it still poses a significant risk. Exploitation could lead to unauthorized manipulation of user-controlled variables, potentially compromising data integrity or system behavior. It is important for administrators and developers to address medium severity issues promptly to prevent potential attacks.
Possible Solutions
To protect your Drupal website from the CVE-2025-10929 vulnerability, the most critical step is to update your Reverse Proxy Header module. The vulnerability affects versions before 1.1.2, which strongly suggests that updating to version 1.1.2 or a newer release will address the flaw. Always ensure you back up your website before performing any updates. It is highly recommended to consult the official Drupal security advisories on drupal.org for the most accurate and up-to-date patch information and instructions.
References
https://www.drupal.org/sa-contrib-2025-111


