Junglewise Threat Intelligence

CVE-2026-76758: Drupal Link content parser unsupported security vulnerability

CVE-2026-76758 · Severity: medium · CVSS 5.9 · Published 2026-09-02

Vendors: Drupal, Packagist:Https://Packages.Drupal.Org/8.

Executive brief

The Drupal Link content parser module is a tool that extracts content from URLs, including articles, titles, images, and summaries. The project maintainer has not fixed a known security vulnerability, and the Drupal security team has marked it as unsupported due to unresolved critical security issues. Organizations using this module should uninstall it or replace it with an actively maintained alternative.

Technical details

The Link content parser module (postlight_parser) contains an unresolved security vulnerability (CVE-2026-76758) that the maintainer has not remediated. The exact nature of the vulnerability is not disclosed in the available reference materials, but the Drupal Security Team has classified it as critical and marked the project as unsupported. The module parses external URL content and extracts data including text, images, and metadata; this functionality could potentially be exploited depending on the underlying vulnerability class. No patch is available from the maintainer, and the project is no longer actively developed. Users should immediately uninstall the module or engage a third-party developer to fix the issue.

Affected products

  • Drupal Link content parser *

Timeline

  • 2026-08-19: advisory: Drupal Security Advisory SA-CONTRIB-2026-101 issued; project marked unsupported
  • 2026-09-02: disclosed: CVE-2026-76758 published

References