Intel

AIKIDO-2026-830072

drupal/entity_share_websub is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-73474 Published 3 days ago

52

Medium Risk

This Affects:

PHPdrupal/entity_share_websub
0.0.1 - 1.1.1
Fixed in 1.1.2
Are you affected? Scan for Free

TL;DR

This module enables content sharing between sites in a hub-subscriber model. Affected versions do not sufficiently validate certain inputs, allowing an attacker to trigger server-side request forgery (SSRF) and cause the application to make unintended requests to internal or external resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/entity_share_websub is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 1.1.1.

How to fix this

Upgrade the drupal/entity_share_websub library to the patch version.