CVE-2025-10929: medium-severity vulnerability in Drupal Reverse Proxy Header
Reverse Proxy Header - Less critical - Access bypass - SA-CONTRIB-2025-111
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
The Reverse Proxy Header module in Drupal improperly validates headers from reverse proxies, allowing attackers to manipulate user information if they can control the proxy headers. This could lead to unauthorized access or identity spoofing in certain configurations.
The vulnerability stems from insufficient validation of HTTP headers (CWE-1288) passed through a reverse proxy, enabling attackers positioned to control or inject proxy headers to manipulate user-controlled variables. An attacker with network access to inject reverse proxy headers can bypass access controls or spoof user identity, affecting versions prior to 1.1.2.