Executive brief
The Clean RESTful module for Drupal, which provides an alternative API for retrieving website content, has been marked as unsupported due to an unpatched critical security vulnerability. Because the maintainer has not addressed the flaw, the Drupal security team recommends that all users immediately uninstall the module to prevent potential unauthorized access or data compromise. Continued use of this software poses a significant risk to the integrity and availability of the affected website.
Technical details
The Drupal Clean RESTful (clean_node_api) module contains an undisclosed critical security vulnerability. The Drupal Security Team issued advisory SA-CONTRIB-2026-078 marking the project as unsupported because the maintainer failed to provide a fix for the reported issue. While specific technical details of the bug class are not public, the advisory classifies the risk as 'Critical' (16/25) with impacts to Confidentiality, Integrity, and Availability. The vulnerability affects all versions of the module. Users are advised to uninstall the module immediately as no patch is available.
Affected products
- Drupal Clean RESTful (clean_node_api) All versions
Timeline
- 2026-07-08: advisory: Drupal Security Team issues SA-CONTRIB-2026-078 marking the project unsupported
- 2026-07-10: disclosed: CVE-2026-15087 published