Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.
History

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 29 Jan 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal http Client Manager
Vendors & Products Drupal
Drupal http Client Manager

Wed, 28 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1.
Title drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation HTTP Client Manager - Less critical - Information disclosure - SA-CONTRIB-2025-126
Weaknesses CWE-754

Fri, 19 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title drupal: Drupal Http Client Manager: Information disclosure due to insufficient data separation
Weaknesses CWE-653
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N'}

threat_severity

Low


cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-01-29T16:30:13.234Z

Reserved: 2025-12-17T17:37:30.402Z

Link: CVE-2025-14840

cve-icon Vulnrichment

Updated: 2026-01-29T16:27:57.847Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-28T20:16:08.623

Modified: 2026-01-29T17:16:15.243

Link: CVE-2025-14840

cve-icon Redhat

Severity : Low

Publid Date: 2025-12-17T17:47:13Z

Links: CVE-2025-14840 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-01-29T09:08:25Z