CVE-2026-58588: Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, from 1.7.0 to 1.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch SA-CONTRIB-2026-066
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58588?
CVE-2026-58588 is categorized as moderately critical.
How do I fix CVE-2026-58588?
To fix CVE-2026-58588, upgrade Drupal Canvas to versions later than 1.7.1.
Which versions of Drupal Canvas are affected by CVE-2026-58588?
CVE-2026-58588 affects Drupal Canvas versions from 0.0.0 to 1.4.2, from 1.5.0 to 1.5.2, from 1.6.0 to 1.6.1, and from 1.7.0 to 1.7.1.
What type of vulnerability is CVE-2026-58588?
CVE-2026-58588 is an Improper Neutralization of Input During Web Page Generation vulnerability, also known as Cross-site Scripting (XSS).
When was CVE-2026-58588 published?
CVE-2026-58588 was published on July 10, 2026.