Drupal · Drupal · CVE-2026-55806
**Name of the Vulnerable Software and Affected Versions**
Drupal core (affected versions not specified)
**Description**
The `rebuild.php` front controller, used to clear caches and rebuild the container when a site is in an unexpected condition, fails to correctly validate the Host header against trusted host patterns. This flaw can lead to cache poisoning, where a cache is filled with a malicious response, or an open redirect, which sends users to an attacker-controlled domain.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.