Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.drupal.org/sa-contrib-2026-025 |
|
History
Thu, 26 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0. | |
| Title | OpenID Connect / OAuth client - Moderately critical - Server-side request forgery, Information disclosure - SA-CONTRIB-2026-025 | |
| Weaknesses | CWE-918 | |
| References |
|
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2026-03-26T20:03:39.756Z
Reserved: 2026-03-04T16:41:58.794Z
Link: CVE-2026-3530
No data.
Status : Received
Published: 2026-03-26T21:17:09.150
Modified: 2026-03-26T21:17:09.150
Link: CVE-2026-3530
No data.
OpenCVE Enrichment
No data.
Weaknesses