❌

Normal view

Project Glasswing

I’m not sure how this slipped under the radar but check this out.

The Drupal Association has been given a grant, and we know from the credits on symfony vulnerabilities that Mythos has scanned them.

This is huge and reassures us that once again, Drupal is, and will remain, the most secure open-source CMS out there.

https://thephp.foundation/blog/2026/05/18/announcing-ecosystem-security-team/

Edit - reworded para 2 based on rereading the context.

submitted by /u/davidrwb
[link] [comments]

Building Drupal at 79 years old

I picked up a new client today. A charity based in the UK.

The β€œwebmaster” (her words) was a 79 year old lady who started Drupal when she was 70.

It was a delight to talk to her and hear her talk about composer, git, and the things we take for granted.

It’s honestly one of the most wholesome things I’ve encountered in my 20+ years of running a Drupal agency.

She wanted a D10 to D11 upgrade and explained about the composer hell she went through. I agreed to help her and estimated a couple of hours to assist. It’s a super simple site, and that’s honestly how long it will take.

Anyway, I wanted to share the story and I hope I’m still doing Drupal at the age of 79 with as much passion as my new client has for her project.

submitted by /u/davidrwb
[link] [comments]

🚨 Drupal Core SQLi (CVE-2026-9082)

Tiny patch, huge impact:

if (is_array($condition['value'])) {
$condition['value'] = array_values($condition['value']);
}

Drupal fixed PostgreSQL placeholder generation by reindexing array keys before query translation.

Without it, attacker-controlled keys could influence SQL placeholder construction.

Affects PostgreSQL-backed Drupal sites.
Anonymous exploitation possible.

Advisory:
[https://www.drupal.org/sa-core-2026-004\](https://www.drupal.org/sa-core-2026-004)

[https://cveplayground.com/blog/cve-2026-9082-drupal-core-sql-injection?utm\\\_source=reddit\](https://cveplayground.com/blog/cve-2026-9082-drupal-core-sql-injection?utm\_source=reddit)

submitted by /u/Protection-Mobile
[link] [comments]

FreshRSS 1.29.1

20 May 2026 at 12:58

This is bug-fix release for 1.29.0.

Feature highlights✨:

  • Accept .txt import of feed URLs in additional to e.g. OPML
  • New CLI for automatic periodic SQLite export with retention
  • More feed info: last received date, publication date

Bug fixes highlights πŸ›:

  • Fix cookies with some browsers
  • Fix search in shared user queries with empty results

UI highlights πŸ–Ό:

  • Improve Web browsers compatibility

This release has been made by @Alkarex, @Frenzie, @IEEE-754, @Inverle, @McFev, @ciro-mota, @cweiske, @polybjorn and newcomer @mzl2233

Full changelog:

  • Features
    • Accept .txt import of feed URLs in additional to e.g. OPML #8818, #8837
    • New CLI for automatic periodic SQLite export with retention #8819
    • More feed info: last received date, publication date #8799
  • Bug fixing
    • Fix cookies with some browsers #8867
    • Fix search in shared user queries with empty results #8863
    • Fix XML errors with loading invalid OPML in lib_opml library #8652, #8853,
      lib_opml#48, lib_opml#51
    • Fix ensure maximum number of feeds also with Dynamic OPML #8832
    • Fix click mark as read #8817
  • UI
    • Improve browser compatibility to keep mobile navigation at the bottom #8833
    • Improve support of older/simpler Web browsers/engines such as SeaMonkey #8810,
      #8811, #8813,
    • Improve Swage theme #8842
    • Rename Nord theme to Nord #8805
    • Replace GIF spinner by CSS spinner #8804, #8812
    • Various UI and style improvements: #8800, #8816,
  • I18n
    • Improve Brazilian Portuguese #8846
    • Improve Dutch #8868
    • Improve German #8840
    • Improve Polish #8854
    • Improve Russian #8861
    • Improve Traditional Chinese #8849
  • Misc.

Hello again everyone, need little more help and showing my progress

Context: https://www.reddit.com/r/drupal/comments/1t884c3/hello_drupal_community_looking_for_help_with/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

Firstly thank you for such detailed suggestions and I am learning Drupal at a good pace, enjoying most of the time and process. I am learning mostly frontend right now and absorbing everything, learning some backend too but not heavily, would go on it later

I would really appreciate some help from your side as you all have been in the Drupal market since so long, I have a drupal interview in coming week, the person said its frontend heavy role, you will be working mostly on the frontend with HTML CSS JS.

While I understand how Drupal architecture works and how to make things and how does this css works here,
I am confused what can I be asked in the interviews, mainly what is asked in Drupal? would they ask me from html css? I come from a full stack web dev background so really no idea how it works in low code interviews, its a part time role. Just 1 round of interview to show my understanding and skills

Any help is good, I will really appreciate, thank you so much !!!

submitted by /u/Critical_System_39
[link] [comments]

Cloud Firewall

May 20, 13:03 UTC
Resolved - Between 06:35 UTC & 12:36 UTC today, our engineering team identified an issue impacting the Cloud Firewall. During this period, users might have encountered issues while updating their firewall rules.

Our team has taken appropriate measures to address the issue. We can confirm that service has been restored and is now functioning normally.

We regret the inconvenience caused and appreciate your patience and understanding. However, if you continue to experience any issues, please create a support ticket for further analysis.

May 20, 12:43 UTC
Monitoring - Our engineering team has implemented a fix that affected the Cloud Firewall rules. Users should now be able to update their firewalls successfully.

We are actively monitoring the situation to ensure overall stability. We appreciate your patience and will provide an update once the issue is fully confirmed as resolved.

May 20, 12:08 UTC
Identified - Our engineering team identified an issue impacting Cloud Firewall Product. During this time, users may notice HTTP 500 errors when updating firewalls.

We apologize for the inconvenience and will share an update once more information is available.

❌