CVE-2026-3216: Drupal Canvas - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-017
Published Mar 25, 2026
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1.
Affected Software
2 affected components
Drupal Drupal Canvas>=0.0.0<1.1.1
Drupal Canvas Project Drupal Canvas Drupal<1.1.1
Event History
Mar 25, 2026
CVE Published
via MITRE·03:24 PM
Data Sourced
via MITRE·03:24 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3216?
CVE-2026-3216 is classified as moderately critical due to its potential for server-side request forgery and information disclosure.
2
How do I fix CVE-2026-3216?
To fix CVE-2026-3216, you should upgrade Drupal Canvas to version 1.1.1 or later.
3
What versions of Drupal Canvas are affected by CVE-2026-3216?
CVE-2026-3216 affects all versions of Drupal Canvas from 0.0.0 up to but not including 1.1.1.
4
What type of vulnerability is CVE-2026-3216?
CVE-2026-3216 is a server-side request forgery (SSRF) vulnerability.
5
What are the potential impacts of CVE-2026-3216?
The potential impacts of CVE-2026-3216 include unauthorized access to sensitive information and possible disclosure of internal network details.