Server-Side Request Forgery in Drupal Entity Share Websub
CVE-2026-73474

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-73474?

A Server-Side Request Forgery (SSRF) vulnerability exists in the Drupal Entity Share Websub, which could allow remote attackers to manipulate server requests or access sensitive data by crafting specific requests. This security flaw is present in Entity Share Websub versions ranging from 0.0.0 to 1.1.2, potentially exposing affected systems to unauthorized information exposure and exploitation.

Affected Version(s)

Entity Share Websub 0.0.0 < 1.1.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcus Johansson (marcus_johansson)
Shawn Duncan (fathershawn)
Jeffrey S. Mattson (jeffreysmattson)
Swan Kalata (akalata)
Neil Drumm (drumm)
Greg Knaddison (greggles)
.