Description
The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.
Remediation
References
Related Vulnerabilities
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3518)
WordPress Plugin BadgeOS SQL Injection (3.7.1.2)
WordPress Plugin Easy Justified Gallery Cross-Site Scripting (1.0.8)
Next.js Acceptance of Extraneous Untrusted Data With Trusted Data Vulnerability (CVE-2026-44572)