Server-Side Request Forgery Vulnerability in Drupal OpenID Connect / OAuth Client
CVE-2026-3530
What is CVE-2026-3530?
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Drupal OpenID Connect and OAuth client, potentially allowing attackers to send unauthorized requests from the server to internal or external resources, which could lead to data exposure or further exploitation. This vulnerability affects versions of the OpenID Connect / OAuth client prior to 1.5.0, emphasizing the necessity of updating to secure the application from potential threats. For more information, visit the official Drupal security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenID Connect / OAuth client 0.0.0 < 1.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
