Drupal Contrib Security
SAML SSO - Service Provider - Moderately critical - Information disclosure - SA-CONTRIB-2026-149
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module stores sensitive authentication information in a manner that could allow disclosure to users with access to configuration or related system data.
This vulnerability is mitigated by the fact that an attacker must first obtain access to configuration or underlying storage mechanisms.
Solution:Install the latest version:
- Upgrade to SAML SSO - Service Provider 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Moderately critical - Embedded credentials - SA-CONTRIB-2026-148
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module contains embedded credentials used by the functionality provided by the module.
Under certain circumstances, these credentials could allow information about associated services to be disclosed.
Solution:Install the latest version:
- Upgrade to miniorange_saml 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-147
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not sufficiently sanitize certain values derived from SAML assertions before displaying them to users. A malicious identity provider or an attacker able to supply crafted SAML attributes, leading to a cross-site scripting (XSS) vulnerability.
Solution:Install the latest version:
- Upgrade to miniorange_saml 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-146
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not sufficiently sanitize user-supplied data before displaying it in generated HTML leading to a cross-site scripting vulnerability (XSS).
Solution:Install the latest version:
- Upgrade to SAML SSO - Service Provider 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Moderately critical - Authentication bypass - SA-CONTRIB-2026-145
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not properly restrict which signature algorithm may be used to validate a SAML assertion, allowing the algorithm to be influenced by the incoming response rather than being tied to the type of key configured for the Identity Provider (IdP).
The vulnerability is mitigated by the fact that an attacker must be able to submit a crafted SAML response to the affected site.
Solution:Install the latest version:
- Upgrade to SAML SSO - Service Provider 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Heine Deelstra (heine) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Critical - Weak cryptographic practices - SA-CONTRIB-2026-144
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module uses cryptographic constructions that do not align with current security best practices.
The module performs certain signature comparisons using non constant-time comparison logic and generates SAML request identifiers using predictable values derived from non-cryptographic random number generation.
While no practical authentication bypass has been demonstrated as a result of these weaknesses alone, they may reduce the overall security margin of SAML authentication workflows.
Solution:Install the latest version:
- Upgrade to SAML SSO - Service Provider 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Critical - Open redirect - SA-CONTRIB-2026-143
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The miniorange_saml module does not sufficiently validate certain user-supplied URLs before performing redirects.
An attacker could cause users to be redirected to an external website after authentication. This could be used in phishing attacks or to increase the credibility of malicious links.
Solution:Install the latest version:
- Upgrade to miniorange_saml 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Critical - Improper certificate validation - SA-CONTRIB-2026-142
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The module does not properly validate TLS certificates when making outbound HTTPS requests.
An attacker in a position to intercept network traffic could impersonate a trusted remote service and influence communications performed by the module.
This vulnerability is mitigated by the fact that an attacker must be able to
intercept or redirect network traffic originating from the site.
Install the latest version:
- Upgrade to miniorange_saml 3.2.0
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SAML SSO - Service Provider - Critical - Improper access control - SA-CONTRIB-2026-141
This module allows you to configure your Drupal site as a SAML 2.0 Service Provider so that users can authenticate through an external identity provider.
The miniorange_saml module does not correctly restrict access to certain functionality intended for administrative use. This could allow unauthorized users to access functionality or modify configuration values that should only be available to privileged users.
Solution:Install the latest version:
- Upgrade to SAML SSO - Service Provider 3.2.0.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
SafeDelete - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-140
This module enables you to manage content deletion and provides reports for identifying orphaned content.
The module doesn't sufficiently sanitize node titles when displaying the orphaned nodes report. This leads to a persistent cross-site scripting vulnerability (XSS).
This vulnerability is mitigated by the fact that an attacker must have permission to create content of a content type configured for the orphaned nodes report.
Solution:Install the latest version:
- If you use the Safe Delete module, upgrade to Safe Delete 1.0.88.
- Lee Rowlands (larowlan) of the Drupal Security Team
- Joseph Olstad (joseph.olstad)
- Lee Rowlands (larowlan) of the Drupal Security Team
- Scott Morrison (scottm316)
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Patreon - Critical - Unsupported - SA-CONTRIB-2026-139
The Drupal Security Team is marking this project unsupported. There is a known security issue with the project that has not been fixed by the maintainer. If you would like to maintain this project, read the documentation on becoming the maintainer of a project that is unsupported for security reasons.
Solution:If you use this project, you should uninstall it.
To take over maintainership, read Becoming the maintainer of a project that is unsupported for security reasons.
Reported By: Coordinated By:- Bram Driesen (bramdriesen) of the Drupal Security Team
- cilefen (cilefen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Key auth - Moderately critical - Access bypass - SA-CONTRIB-2026-138
This module enables you to add key-based authentication on a per-user
basis.
The module doesn't cache per user, potentially allowing an attacker to view another user's authentication keys, if the attacker has the same permissions.
This vulnerability is mitigated by the fact that the site must have the dynamic_page_cache module enabled.
Solution:Install the latest version:
- If you use the Key Auth module, upgrade to Key auth 2.2.4.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137
The Feed Block module provides a block content type that displays items pulled from a remote RSS/Atom feed.
The module does not sufficiently validate or sanitize the RSS feed it generates, resulting in a stored cross-site scripting (XSS) vulnerability.
Solution:Install the latest version:
- If you use the 3.x branch, upgrade to Feed Block 3.0.2.
- If you use the 2.x branch, upgrade to Feed Block 2.0.2.
- Greg Knaddison (greggles) of the Drupal Security Team
- Mark Fullmer (mark_fullmer)
- mmarler
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136
The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to an account with the Access CSP reports permission to exploit the SQL Injection.
Solution:Install the latest version:
- If you use the CSP Log module, upgrade to CSP Log 1.0.2.
- Ivo Van Geertruyen (mr.baileys) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Central Authentication System (CAS) Server - Moderately critical - Open redirect - SA-CONTRIB-2026-135
This module enables you to turn a Drupal install into the Central Authentication System (CAS) Server. It makes your database the primary location for other systems to use for authentication in a SSO environment.
The module doesn't sufficiently check the service URL used to redirect the user during logout, leading to an open redirect.
This vulnerability is mitigated by the fact that an attacker must convince a user to click a specially crafted link. The vulnerability cannot be exploited without user interaction and does not allow an attacker to directly compromise the CAS server or bypass authentication.
Solution:Install the latest version of Central Authentication System (CAS) Server module:
- If you use the 2.0.x branch, upgrade to CAS Server 2.0.4.
- If you use the 2.1.x branch, upgrade to CAS Server 2.1.3
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
amazee.ai Private AI Provider - Critical - SQL injection - SA-CONTRIB-2026-134
Update 2026-09-11: Increased risk score to reflect publicly documented methods for developing exploits.
This module integrates amazee.ai's AI services into Drupal, including a Postgres/pgvector vector database backend for use with Search API AI Search.
The module doesn't sufficiently sanitize filter values before using them to build SQL queries in its Postgres/pgvector backend, allowing SQL injection.
This vulnerability is mitigated by the fact that a site must be using the module's Postgres/pgvector vector database backend for a Search API AI Search index, and must expose one of that index's non-string fields as a filter (for example, through a View) that is reachable by the attacker.
Solution:Install the latest version:
- If you use the amazee.ai AI Provider module for Drupal 1.4.x, upgrade to ai_provider_amazeeio 1.4.3.
- If you use the 1.3.x branch, upgrade to ai_provider_amazeeio 1.3.7.
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Swan Kalata (akalata) of the Drupal Security Team
Webform Submissions Delete - Moderately critical - Access bypass - SA-CONTRIB-2026-133
This module enables you to delete Webform submissions in bulk using a specified date range.
The module doesn't sufficiently restrict access to the delete form.
A separate PHP fatal error issue may prevent exploitation in practice on Drupal 10+.
Solution:Install the latest version:
- If you use the Webform Submissions Delete module, upgrade to Webform Submissions Delete 8.x-1.2
- Swan Kalata (akalata) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Dan Smith (galooph) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
Unpublished Node Permissions - Critical - Access bypass - SA-CONTRIB-2026-132
This module creates permissions per node content type to control access to unpublished content.
The module has allowed view access for published content, overriding other access mechanisms that might have been in place.
Solution:Install the latest version:
- If you use the Unpublished Node Permissions module, upgrade to Unpublished Node Permissions 8.x-1.8.
- Swan Kalata (akalata) of the Drupal Security Team
- Damien McKenna (damienmckenna) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
PhotoSwipe - Responsive JavaScript Modal Image Gallery - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-131
This module enables you to add dynamic caption support to PhotoSwipe image galleries.
The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
Solution:Install the latest version:
- If you use the photoswipe_dynamic_caption module, upgrade to photoswipe 5.0.9
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Joshua Sedler (grevil)
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team
Monobank payment API - Moderately critical - Access bypass - SA-CONTRIB-2026-130
The Monobank payment API module provides integration with Monobank acquiring payments.
The module did not verify the Monobank webhook signature before processing payment status callbacks.
Solution:Install the latest version:
- If you use the Monobank payment API module, upgrade to the monobank 1.0.3.
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team

Neue Kommentare
vor 2 Wochen 3 Tagen
vor 2 Wochen 6 Tagen
vor 3 Wochen 23 Stunden
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 3 Tagen
vor 3 Wochen 6 Tagen
vor 4 Wochen 13 Stunden
vor 4 Wochen 21 Stunden