View online: https://www.drupal.org/sa-contrib-2026-136 Project: CSP log [1] Date: 2026-September-09 Security risk: *Critical* 15 ∕ 25 AC:Basic/A:Admin/CI:All/II:Some/E:Theoretical/TD:All [2] Vulnerability: SQL Injection Affected versions: <1.0.2 CVE IDs: CVE-2026-87938 Description: The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers. The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability. This vulnerability is mitigated by the fact that an attacker needs access to an account with the /Access CSP reports/ permission to exploit the SQL Injection. Solution: Install the latest version: * If you use the CSP Log module, upgrade to CSP Log 1.0.2 [3]. Reported By: * eduardo morales alberti [4] Fixed By: * Ivo Van Geertruyen (mr.baileys) [5] of the Drupal Security Team Coordinated By: * Bram Driesen (bramdriesen) [6] of the Drupal Security Team * Greg Knaddison (greggles) [7] of the Drupal Security Team * Jess (xjm) [8] of the Drupal Security Team * Swan Kalata (akalata) [9] of the Drupal Security Team ------------------------------------------------------------------------------ Contribution record [10] [1] https://www.drupal.org/project/csp_log [2] https://www.drupal.org/security-team/risk-levels [3] https://www.drupal.org/project/csp_log/releases/1.0.2 [4] https://www.drupal.org/u/eduardo-morales-alberti [5] https://www.drupal.org/u/mrbaileys [6] https://www.drupal.org/u/bramdriesen [7] https://www.drupal.org/u/greggles [8] https://www.drupal.org/u/xjm [9] https://www.drupal.org/u/akalata [10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal....