it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136
- Date: Wed, 9 Sep 2026 17:16:34 +0000
- Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=nOd4chAC; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=0L2iFT+r; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=nOd4chAC; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=0L2iFT+r; arc=none smtp.remote-ip=54.240.27.35
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 6D40D40D18
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 55EFD40055
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975222; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=gIoRvvRy49uNVp/oBvPe9ryMeCt6nIGUWe7CNcw7wps=; b=cZEBM1uusDtdiPmA7ZbYHL0Xjy1Df++RA/pLHngFrNGhgL8u9rmNqDnZkvve+E2huF4x pkWgwlP4PYGNVcty6tQDPl0XBemBQk3kNSHj/EovEsJ50lQ8s/a2oG6srrV93y74tFkWi +qDWZyYS77EHNAXu0ysoMAGC1t6yQoF6ttlXENfZelVnzHhn0Ustcs/cO7FZDJXjK9lJm OwIzlIyEyPKw4ueejqrOuS5yceSxQErZ4m4gs6jJIKB0hKFaqzBCG9ERHD2sGRiOnTtO4 9o/L/1PgVZoi0yt60kTkvPNHkyvzzStAAMaydfLezO6cWApcrGK84wA2Ea0lTstzfzA==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974195; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=HaNGwsjaHejN9VZ1VwHwnHrmTKKfaLHc7gwC4BxnbRc=; b=ibZJrz0o14fufukvrJAcv5lqTSmgDE8zarySByHJ486apOb3If7xg0NBblYhCsr/X87D sIOPLHcwaweQ3PE0BaKUpTgB7l97kJIqp1gUR9cNbnjQ9YoWGbzyZXJTB/b69TXgPTAGI j6M0IE09ABn6W3al79K3jIlM4ZZojOY42ysKsn+ygAZ4kzfpJbLaDA78HlGvaZdexG886 1Mq4ME1DLWsnuBzNxCcTX+4plzXmn/gePEf2ioNyey335FhMD1c7FaZaY61UVbnBSNmsE 4VFjBt2d04XgANHU38lTzEjxb+QUnVBQnAMubNqh089B4QL5oepy6ks2VmwucajYYJg==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975222; b=gBZfsrlBeE9AkbGpatpxEG1IdRRJezaz5cAiMgMGW/+JgoqFumFYO3DvxicivrRy9ci5 v/dMUegbzEwxQU3ef2EMebTLyrMlWUVHDlmQ2eGJZp5CsIdVwdzW1Hj+CrayA165o+SSA RGvFiP/ZuCLE4vRQhjp2LeHhh7vyTeDCzJMm3PZJdIMqSO3UUKIvm8spowV1UNkliwji9 hDy5J7AkyBUMUvMUCKv6IENQjZJPwbp4uhHD1pZBYUcROIAhF4eZZQsktRGm9smY/GxU2 nK6nHYOYDOlxbKPI9FZq4cpe0N6/XYgQvlHvhBCeLpdbxssKYdqgrXx3raPy2mrI9cQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974195; b=taOQmZa/zEfynsBjJZhR+iqtxSQ/ieKTjdkcJeQQNWweIZHRW+j/NUiMZHGpejoXJCfu LDSoDROrgVTiw4S1KeTrAK/kGh2SOcVGzdRsLXb/S0rsb5m78wNhzUKPNr9bupZnysAOd nqhEfSY+FlMzgwi6JMPG59ieHJASXTaH/Iix17mYJTcoZgMzPHREfAkT+L00AA+auxMN9 HLaTRiHjn0Ec1n85xDp0frP1Ep3UN1BaeCWv8CXux25SNHD927UdrxCM/OAgURItB4dJi 0jIjNFk1v/UVo9CWhqH+L5QIn6qbH7jIuc255mWpDYmeT9aAotUUIrCsv2d5cmULUSg==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/YCHWPBQOKP6WK3JRKCRFFORJ446UZWMO/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Vv9fIvKd; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=nOd4chAC; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=0L2iFT+r; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-136
Project: CSP log [1]
Date: 2026-September-09
Security risk: *Critical* 15 ∕ 25
AC:Basic/A:Admin/CI:All/II:Some/E:Theoretical/TD:All [2]
Vulnerability: SQL Injection
Affected versions: <1.0.2
CVE IDs: CVE-2026-87938
Description:
The CSP Log module enhances any module that adds the CSP header to a site, by
providing a reporting endpoint, custom storage, and aggregated reports that
can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in
database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to
an account with the /Access CSP reports/ permission to exploit the SQL
Injection.
Solution:
Install the latest version:
* If you use the CSP Log module, upgrade to CSP Log 1.0.2 [3].
Reported By:
* eduardo morales alberti [4]
Fixed By:
* Ivo Van Geertruyen (mr.baileys) [5] of the Drupal Security Team
Coordinated By:
* Bram Driesen (bramdriesen) [6] of the Drupal Security Team
* Greg Knaddison (greggles) [7] of the Drupal Security Team
* Jess (xjm) [8] of the Drupal Security Team
* Swan Kalata (akalata) [9] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [10]
[1] https://www.drupal.org/project/csp_log
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/csp_log/releases/1.0.2
[4] https://www.drupal.org/u/eduardo-morales-alberti
[5] https://www.drupal.org/u/mrbaileys
[6] https://www.drupal.org/u/bramdriesen
[7] https://www.drupal.org/u/greggles
[8] https://www.drupal.org/u/xjm
[9] https://www.drupal.org/u/akalata
[10] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3621339
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] CSP log - Critical - SQL Injection - SA-CONTRIB-2026-136, security-news, 09.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.