Improper Condition Check in Drupal's HTTP Client Manager Affects Multiple Versions
CVE-2025-14840

7.5HIGH

Key Information:

Vendor

Drupal

Vendor
CVE Published:
28 January 2026

What is CVE-2025-14840?

A vulnerability in the HTTP Client Manager of Drupal has been identified, which permits unauthorized access through forceful browsing. This issue is linked to improper checks for unusual conditions in the application's security framework, potentially allowing attackers to navigate to restricted resources without proper authentication. It affects several versions of the HTTP Client Manager, leaving users susceptible to security breaches. Timely updates are essential to safeguard against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

HTTP Client Manager 0.0.0 < 9.3.13

HTTP Client Manager 10.0.0 < 10.0.2

HTTP Client Manager 11.0.0 < 11.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mxh
Adriano Cori (aronne)
mxh
Greg Knaddison (greggles)
Juraj Nemec (poker10)
.