Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_products Red Hat · All currently supported Red Hat products | not affected vulnerable code not present | no version stated | not applicable | csaf_redhat | |
| drupal | affected | >= 8.9.0, < 10.4.10 | vendor fix → 10.4.10 | osv BIT-drupal-2026-9082 | |
| drupal | affected | >= 10.5.0, < 10.5.10 | vendor fix → 10.5.10 | osv BIT-drupal-2026-9082 | |
| drupal | affected | >= 10.6.0, < 10.6.9 | vendor fix → 10.6.9 | osv BIT-drupal-2026-9082 | |
| drupal | affected | >= 11.0.0, < 11.1.10 | vendor fix → 11.1.10 | osv BIT-drupal-2026-9082 | |
| drupal | affected | >= 11.2.0, < 11.2.12 | vendor fix → 11.2.12 | osv BIT-drupal-2026-9082 | |
| drupal | affected | >= 11.3.0, < 11.3.10 | vendor fix → 11.3.10 | osv BIT-drupal-2026-9082 | |
| drupal/core | affected | >= 8.9.0, < 10.4.10 | vendor fix → 10.4.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | affected | >= 10.5.0, < 10.5.10 | vendor fix → 10.5.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | affected | >= 10.6.0, < 10.6.9 | vendor fix → 10.6.9 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | affected | >= 11.0.0, < 11.1.10 | vendor fix → 11.1.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | affected | >= 11.2.0, < 11.2.12 | vendor fix → 11.2.12 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | affected | >= 11.3.0, < 11.3.10 | vendor fix → 11.3.10 | osv GHSA-ghwc-95x2-682j | |
| https://git.drupalcode.org/project/drupal | affected | >= a412ca41cfc0d954fe3cb2dd982dc6ca049b1c70, < b6a15bbe200725c195a01e86f058059650e24d8d | vendor fix → b6a15bbe200725c195a01e86f058059650e24d8d | osv | |
| https://git.drupalcode.org/project/drupal | affected | >= d4b39f784711f3b861d59c37ec8e9f5592b623ce, < 064f2a61e4d30eb2949ec5e3ec77d8f5cecd2a87 | vendor fix → 064f2a61e4d30eb2949ec5e3ec77d8f5cecd2a87 | osv | |
| https://git.drupalcode.org/project/drupal | affected | >= 920f3f7ab87ba2cca9191ec292d356197de4bc0a, < ded704bfa93b9037cb312057abab97d89746ea36 | vendor fix → ded704bfa93b9037cb312057abab97d89746ea36 | osv | |
| https://git.drupalcode.org/project/drupal | affected | >= 140f94ff1051644c4416c7ed30cc5dd1f14507b2, < fe5b9e6d3961e05cc549b935e05f533f0fb4939b | vendor fix → fe5b9e6d3961e05cc549b935e05f533f0fb4939b | osv | |
| https://git.drupalcode.org/project/drupal | affected | >= 338d58439d5b59d92ac9519ad81ffd916b673841, < ce6f20a43d1119288b51f2c452644ba7ea1fab61 | vendor fix → ce6f20a43d1119288b51f2c452644ba7ea1fab61 | osv | |
| https://git.drupalcode.org/project/drupal | affected | >= ac5da07ad88571dbb31dfb52f055bb0d4063f598, < 26adc3e4f17a0710db766703c0aa761cc26e0112 | vendor fix → 26adc3e4f17a0710db766703c0aa761cc26e0112 | osv | |
| drupal | fixed | 10.4.10 | vendor fix → 10.4.10 | osv BIT-drupal-2026-9082 | |
| drupal | fixed | 10.5.10 | vendor fix → 10.5.10 | osv BIT-drupal-2026-9082 | |
| drupal | fixed | 10.6.9 | vendor fix → 10.6.9 | osv BIT-drupal-2026-9082 | |
| drupal | fixed | 11.1.10 | vendor fix → 11.1.10 | osv BIT-drupal-2026-9082 | |
| drupal | fixed | 11.2.12 | vendor fix → 11.2.12 | osv BIT-drupal-2026-9082 | |
| drupal | fixed | 11.3.10 | vendor fix → 11.3.10 | osv BIT-drupal-2026-9082 | |
| drupal/core | fixed | 10.4.10 | vendor fix → 10.4.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | fixed | 10.5.10 | vendor fix → 10.5.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | fixed | 10.6.9 | vendor fix → 10.6.9 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | fixed | 11.1.10 | vendor fix → 11.1.10 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | fixed | 11.2.12 | vendor fix → 11.2.12 | osv GHSA-ghwc-95x2-682j | |
| drupal/core | fixed | 11.3.10 | vendor fix → 11.3.10 | osv GHSA-ghwc-95x2-682j | |
| https://git.drupalcode.org/project/drupal | fixed | b6a15bbe200725c195a01e86f058059650e24d8d | vendor fix → b6a15bbe200725c195a01e86f058059650e24d8d | osv | |
| https://git.drupalcode.org/project/drupal | fixed | 064f2a61e4d30eb2949ec5e3ec77d8f5cecd2a87 | vendor fix → 064f2a61e4d30eb2949ec5e3ec77d8f5cecd2a87 | osv | |
| https://git.drupalcode.org/project/drupal | fixed | ded704bfa93b9037cb312057abab97d89746ea36 | vendor fix → ded704bfa93b9037cb312057abab97d89746ea36 | osv | |
| https://git.drupalcode.org/project/drupal | fixed | fe5b9e6d3961e05cc549b935e05f533f0fb4939b | vendor fix → fe5b9e6d3961e05cc549b935e05f533f0fb4939b | osv | |
| https://git.drupalcode.org/project/drupal | fixed | ce6f20a43d1119288b51f2c452644ba7ea1fab61 | vendor fix → ce6f20a43d1119288b51f2c452644ba7ea1fab61 | osv | |
| https://git.drupalcode.org/project/drupal | fixed | 26adc3e4f17a0710db766703c0aa761cc26e0112 | vendor fix → 26adc3e4f17a0710db766703c0aa761cc26e0112 | osv | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 8.9.0, < 10.4.10 | none available | cve_cna | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 10.5.0, < 10.5.10 | none available | cve_cna | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 10.6.0, < 10.6.9 | none available | cve_cna | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 11.0.0, < 11.1.10 | none available | cve_cna | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 11.2.0, < 11.2.12 | none available | cve_cna | |
| Drupal/Drupal core Drupal · Drupal core | affected | >= 11.3.0, < 11.3.10 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.