SA-CONTRIB-2026-097: Critical severity drupal/entity_share_websub vulnerability
This module enables you to share content between sites in a hub - subscriber model. Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
drupal/entity_share_websubto a version that resolves this vulnerability.Fixed in 1.1.2
Event History
Frequently Asked Questions
What is the severity of SA-CONTRIB-2026-097?
The severity of SA-CONTRIB-2026-097 is critical, rated at 9.
How do I fix SA-CONTRIB-2026-097?
To fix SA-CONTRIB-2026-097, you should update the Drupal entity_share_websub module to the latest version that addresses this vulnerability.
What is the risk associated with SA-CONTRIB-2026-097?
The risk associated with SA-CONTRIB-2026-097 is a potential server-side request forgery attack due to insufficient input validation.
When was SA-CONTRIB-2026-097 published?
SA-CONTRIB-2026-097 was published on August 12, 2026.
What functionality does SA-CONTRIB-2026-097 provide?
SA-CONTRIB-2026-097 enables sharing content between sites in a hub-subscriber model.