Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
935 articles · 105089 vulns · 39/41 feeds (7d)
← Back to list
—
CVE-2026-3530
Drupal · OpenID Connect OAuth client

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

Description

Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.

Affected Products

VendorProductVersions
DrupalOpenID Connect OAuth client1.4.x

References

  • https://www.drupal.org/sa-contrib-2026-025

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-3530 | OpenID Connect OAuth client up to 1.4.x on Drupal server-side request forgery (sa-contrib-2026-025)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-918
Published3/26/2026
Last enriched27m agov2
Trending Score20
Source articles1
Independent1
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v2
Last enriched 27m ago
v2Tier C27m ago

Updated vendor to Drupal, product to OpenID Connect OAuth client, set severity to CRITICAL, and specified affected versions as 1.4.x with patch available at 1.5.0.

vendorproductaffectedVersionspatchAvailable
via VulDB
v12h ago

Initial creation