Executive brief
Entity Share Websub is a Drupal module that automates content synchronization between Drupal sites using a hub-subscriber model. A server-side request forgery vulnerability in the module allows attackers to send crafted requests from the affected server to internal or external systems, potentially accessing sensitive data or services not directly exposed to the attacker. This could lead to unauthorized access to internal resources or information disclosure.
Technical details
The vulnerability is a server-side request forgery (SSRF) caused by insufficient validation of user inputs in the Entity Share Websub module. An attacker can exploit this vulnerability to forge requests from the vulnerable server to arbitrary internal or external systems. The attack requires network access to the affected Drupal site but does not require authentication. By leveraging this SSRF flaw, attackers can potentially probe internal networks, access restricted resources, or retrieve sensitive metadata. The vulnerability affects Entity Share Websub versions prior to 1.1.2, and patches are available in version 1.1.2 and later.
Affected products
- Drupal Entity Share Websub before 1.1.2
Timeline
- 2026-08-12: disclosed
- 2026-08-12: patched: Version 1.1.2 released