Intel

AIKIDO-2026-830072

drupal/entity_share_websub is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-73474 Published Aug 18, 2026

52

Medium Risk

This Affects:

PHPdrupal/entity_share_websub
0.0.1 - 1.1.1
Fixed in 1.1.2
Are you affected? Scan for Free

TL;DR

This module enables content sharing between sites in a hub-subscriber model. Affected versions do not sufficiently validate certain inputs, allowing an attacker to trigger server-side request forgery (SSRF) and cause the application to make unintended requests to internal or external resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/entity_share_websub is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 1.1.1.

How to fix this

Upgrade the drupal/entity_share_websub library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform