View online: https://www.drupal.org/sa-contrib-2026-097 Project: Entity Share Websub [1] Date: 2026-August-12 Security risk: *Critical* 15 ∕ 25 AC:Basic/A:None/CI:All/II:None/E:Theoretical/TD:All [2] Vulnerability: Server-side request forgery (SSRF) Affected versions: <1.1.2 CVE IDs: CVE-2026-73474 Description: This module enables you to share content between sites in a hub - subscriber model. Certain inputs were not sufficiently validated, allowing an attacker to achieve server-side request forgery attacks. Solution: Install the latest version: * If you use the Entity Share Websub module for Drupal 9.x or 10.x, upgrade to Entity Share Websub 1.1.2 [3] Reported By: * Marcus Johansson (marcus_johansson) [4] Fixed By: * Shawn Duncan (fathershawn) [5] * Jeffrey S. Mattson (jeffreysmattson) [6] Coordinated By: * Swan Kalata (akalata) [7] of the Drupal Security Team * Neil Drumm (drumm) [8] of the Drupal Security Team * Greg Knaddison (greggles) [9] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/entity_share_websub [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/entity_share_websub/releases/1.1.2 [4] https://www.drupal.org/u/marcus_johansson [5] https://www.drupal.org/u/fathershawn [6] https://www.drupal.org/u/jeffreysmattson [7] https://www.drupal.org/u/akalata [8] https://www.drupal.org/u/drumm [9] https://www.drupal.org/u/greggles [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....