Drupal Security Team Marks Three Contributed Projects Unsupported

Promotional graphic from The Drop Times regarding a Drupal Security Advisory dated 10 June 2026. The text highlights critical advisories affecting the 'Composer' and 'Brute force attack protection' projects due to unfixed security issues.

Sites using Mother May I, Composer, or Brute force attack protection should uninstall the projects after Drupal.org published three critical contributed-project advisories on 10 June 2026. The Drupal Security Team marked all three projects unsupported for security reasons. Drupal.org lists every released version as affected and provides no patched release.

Unsupported-project advisories leave affected sites without an update path. Each of the three advisories says the project has a known security issue that has not been fixed by its maintainer. The advisories do not disclose technical exploit details or identify the affected code paths.

SA-CONTRIB-2026-045 applies to Mother May I. Drupal.org assigned the issue CVE-2026-11913 and rated it Critical 16/25. The advisory lists all versions as affected and tells sites using the project to uninstall it.

SA-CONTRIB-2026-046 applies to the Composer project. Drupal.org assigned the issue CVE-2026-11914 and rated it Critical 16/25. The advisory states that it concerns a Drupal project that makes use of Composer, not the Composer dependency manager itself.

SA-CONTRIB-2026-047 applies to Brute force attack protection. Drupal.org assigned the issue CVE-2026-11915 and gave it the same Critical 16/25 rating. All released versions are listed as affected, and Drupal.org advises sites using the project to uninstall it.

All three advisories classify the vulnerability as Unsupported. They also direct prospective maintainers to Drupal's process for taking over a project that is unsupported for security reasons. A future return to supported status would require the unresolved security issue and project maintainership to be addressed.

Site administrators should check whether any of the three projects are present in their codebase before planning further action. The advisories do not identify direct substitutes for the affected projects. Replacement decisions therefore depend on the requirements of each site.

Correction, 24 August 2026: An earlier version of this story omitted the Mother May I advisory and incorrectly reported that Drupal.org published two unsupported-project advisories on 10 June 2026. Drupal.org published three such advisories that day. The story has been updated to include Mother May I and SA-CONTRIB-2026-045.

Disclosure: This content is produced with the assistance of AI.

Note: The vision of this web portal is to help promote news and stories around the Drupal community and promote and celebrate the people and organizations in the community. We strive to create and distribute our content based on these content policy. If you see any omission/variation on this please reach out to us at #thedroptimes channel on Drupal Slack and we will try to address the issue as best we can.

Upcoming Events

Latest Opportunities