Drupal · Drupal Http Client Manager · CVE-2025-14840
**Name of the Vulnerable Software and Affected Versions**
Drupal HTTP Client Manager versions prior to 9.3.13
Drupal HTTP Client Manager versions 10.0.0 through 10.0.2
Drupal HTTP Client Manager versions 11.0.0 through 11.0.1
**Description**
An improper check for unusual or exceptional conditions exists in the Drupal HTTP Client Manager, potentially allowing for forceful browsing. This issue relates to how the HTTP Client Manager handles certain conditions, which could be exploited.
**Recommendations**
Update Drupal HTTP Client Manager to a version beyond 9.3.13.
Update Drupal HTTP Client Manager to a version beyond 10.0.2.
Update Drupal HTTP Client Manager to a version beyond 11.0.1.