Project:
Date:
2026-August-12
Vulnerability:
Server-side request forgery (SSRF)
Affected versions:
<1.1.2
CVE IDs:
CVE-2026-73474
Description:
This module enables you to share content between sites in a hub - subscriber model.
Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks.
Solution:
Install the latest version:
- If you use the Entity Share Websub module for Drupal 9.x or 10.x, upgrade to Entity Share Websub 1.1.2
Reported By:
Coordinated By:
- Swan Kalata (akalata) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team