Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
937 articles · 105108 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-3530
Drupal · OpenID Connect OAuth client

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

Description

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

Affected Products

VendorProductVersions
DrupalOpenID Connect OAuth client1.4.x

References

  • https://www.drupal.org/sa-contrib-2026-025

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-3530 | OpenID Connect OAuth client up to 1.4.x on Drupal server-side request forgery (sa-contrib-2026-025)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-918
Published3/26/2026
Last enriched2h agov2
Trending Score20
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated vendor to Drupal, product to OpenID Connect OAuth client, set severity to CRITICAL, and specified affected versions as 1.4.x with patch available at 1.5.0.

vendorproductaffectedVersionspatchAvailable
via VulDB
v14h ago

Initial creation