Maintenance and security release of the Drupal 8 series.
This release fixes security vulnerabilities. Sites are urged to upgrade immediately after reading the notes below and the security announcement:
- Drupal Core – Third-party libraries – SA-CORE-2019-001
- Drupal Core – Arbitrary PHP code execution – SA-CORE-2019-002
No other fixes are included.
Versions of Drupal 8 prior to 8.5.x are end-of-life and do not receive security coverage. Sites on 8.5.x will receive security coverage until May 2019.
Important update information
.pharfile extension has been added to Drupal’s dangerous extensions list, which means that any such file uploaded to a Drupal file field will automatically be converted to a text file (with the
.txtextension) to prevent it from being executed. This is similar to how Drupal handles file uploads with a
No changes have been made to the .htaccess, web.config, robots.txt or default settings.php files in this release, so upgrading custom versions of those files is not necessary.
Users are reporting seeing a fatal error when updating their sites with Drush. Site owners may be able to run
drush updb and either
drush cc all or
drush cr depending on the version to complete the update. Check the status report afterward to confirm that Drupal has been updated. See for details.