Drupal HTTP Client Manager Forceful Browsing Vulnerability

Vulnerability

A vulnerability allowing forceful browsing has been identified in the Drupal HTTP Client Manager. This issue arises from improper handling of data separation in HTTP request operations, which could lead to information disclosure in rare circumstances. The vulnerability affects HTTP Client Manager versions prior to 9.3.13, as well as versions 10.0.0 prior to 10.0.2 and 11.0.0 prior to 11.0.1.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure.

Remediation

Users of the HTTP Client Manager module should upgrade to version 9.3.13, 10.0.2, or 11.0.1, depending on their current version.

Added: Jan 28, 2026, 8:33 PM
Updated: Jan 28, 2026, 8:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.