CVE-2026-58587: Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Drupal Canvasto a version that resolves this vulnerability.Fixed in 1.4.2 - Upgrade
Upgrade
Drupal Canvasto a version that resolves this vulnerability.Fixed in 1.5.2 - Upgrade
Upgrade
Drupal Canvasto a version that resolves this vulnerability.Fixed in 1.6.1 - Upgrade
Upgrade
Drupal Canvasto a version that resolves this vulnerability.Fixed in 1.7.1 - Upgrade
Upgrade
Drupal Canvasto a version that resolves this vulnerability.Patch SA-CONTRIB-2026-065
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58587?
CVE-2026-58587 has a moderately critical risk rating.
How do I fix CVE-2026-58587?
To fix CVE-2026-58587, update Drupal Canvas to version 1.4.3 or later, or 1.5.3 or later for affected ranges.
What impact does CVE-2026-58587 have on my Drupal site?
CVE-2026-58587 allows attackers to perform Cross-Site Scripting (XSS) on vulnerable Drupal sites.
Which versions of Drupal Canvas are affected by CVE-2026-58587?
CVE-2026-58587 affects Drupal Canvas versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1.
What is Cross-Site Scripting in relation to CVE-2026-58587?
Cross-Site Scripting (XSS) in CVE-2026-58587 occurs when the application improperly validates input during web page generation.