Visit Drupal NES Home Page

Captcha Release Notes

1 version

Comprehensive release notes and changelog for Captcha, including security patches, bug fixes, and feature updates across all supported versions.

Apr 7, 2026
Latest: 7.1.8
2 Patched Vulnerabilities
VEX Statements

April 2026

Full Version:
7.1.8+7.1.7:captcha

Notes

This is the initial NES release of the Captcha module.

Changes

  • Security: Fix CVE-2026-3214 CAPTCHA session replay bypass (SA-CONTRIB-2026-015).
  • Security: Replace md5(mt_rand()) with bin2hex(drupal_random_bytes(16)) for token generation.
  • PHP 8.3: Cast jitter bounds to int before mt_rand() in image_captcha.user.inc.
  • Testing: Harden image CAPTCHA test to assert HTTP 200 and Content-Type instead of body length.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.