Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137
  • Date: Wed, 9 Sep 2026 17:16:59 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=VdoJvJSE; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="onMbK/vC"; arc=none smtp.remote-ip=54.240.27.123
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 41EA9415CB
  • Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 3B8A4407AE
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788975265; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=DlDHzrxrou+m6zqSwco3bH5lRzMKlk6Sn5gG9kFJgR0=; b=EhoKjNPZa/PCTpxQ1EUkRJFvWwQ8uHJbQs6W91Hbi9S4gmmnf/0vr5Ws6NjdJ8+uu8eJ npFi4FwKzyGgOd/aAHADQfm9JaPdjvybdI0tLHg+A8fuFw9wtkUBW7ifpenbECBlacbMm 4tl2GLoWwIMFvU0jtfpoCcLPaqbg/j7o2TGda8pl9yGpB2Wl+fcS4Jcd+BJwwTUhpauav vep6CuIYQb2aCQviDzm7BmSC3gjYkF1W+bMAhXMRPx4oml0Nvvicqb59du3np6AUwE3S8 dj4VvX4MHbZe4WnWSTUCu1NxOIRjAsmPwtH9KXUpFwpbRxvpLXlWH37YqL2/vv98Aag==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1788974220; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=EXX8cb81zX8COMjHGFZEHKKskbjtIyvg2s4hHThJ6ck=; b=Tecp/fvwsooVgmYQMCh0YJpVP5U2gSM2PrgEhJu0IJWCK2dWSd5kv8ypG7c3sH9FyJmm JrYgMRl5bIqSUqafFHc2La0W9vHuc8Up1DaCEvySQxjhDn7w+4Z7drL0ftBGaVxiAuCUT 8mDYOJGqgl/yZWFRfAYFmelgZXxeb5nrMO8fU/VNJ+Pv29hi6PDodEysA0Oar2YGQYiIA Pca7wLOrxT6FcleLo7QJjBw4BVImMXRg/dshc61yqnLtwkBS8bRf3HZq/Ttih5AORIXAC 6GjjTBx/uAQpirfdbiA1/7h+jYunEF6nKcutrXi2wRdYH5b0iiZlvvqhY8i2Eyhl3tA==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1788975265; b=ZWLz9We6DK8NTpS5oEx2ieB0X3PGVAtgK3steod5kNTQ2QbpoeyMDfYPnJhBTgnDllAb J2LSelYDlfmzyOqOg0r2KWsFaUiBOYPeKb2waW6zBVwQ4VFdJZGtbWALadTKX8v7VBzO1 BdGRz72ljnlfqZj4A8+r/gFfhW6wOSGgxviu7+k2xHl7yrrCMC0YPCVlGzZDNyihLW7nC xgfPlbF2zrtsdPWPgiqgyjBHfF45GT2+i2CGGdXG5M8IqgLas/dy8xgPcg7o7A2XxSaWU un1pRKdwJv/G8iQQFtep7qH7AYyzNMaqTyU+SoGTnJrn5CCafMIHdFsMN4MFzUCZ0Rw==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1788974220; b=J/DBEdeKc7DcWsUbMWInBo7HyapKQF8t9jtonMhLeT8nRZL0SF84UY8Zb6ITqpKclQZj n4Y35HAPWw19pMPNcehLpTXsWopyO+z9u+fdZ4beYTBAWzRnUr+FVodROQIcmaGpolYgr MsT/0kt1/XchTprX6kbbllmm6a4Pb4cwCCVBBkoYbeTnAPLnC4d10x7x5mFbxbpqLCprn DP9q8h7ZEZdzHZvg0Kte1LXAah9Las1+0XJUzmmSzNmoVr/6n0iP6K7kvipBsKI8Si3VS aQ1OU7ah6H1v5fc55Yck4X1x6xPjnzw2peTI+jCBKedIuN1oafQX1hzsRmTNKSr39XQ==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/WYD7NUTMXRS3XKC3QN5ZOFAPDLPP6WJS/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=KCkofVru; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=VdoJvJSE; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="onMbK/vC"; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-137

Project: Feed Block [1]
Date: 2026-September-09
Security risk: *Moderately critical* 13 ∕ 25
AC:Complex/A:User/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Cross-site scripting

Affected versions: <2.0.2 || >=3.0.0 <3.0.2
CVE IDs: CVE-2026-87939
Description: 
The Feed Block module provides a block content type that displays items
pulled from a remote RSS/Atom feed.

The module does not sufficiently validate or sanitize the RSS feed it
generates, resulting in a stored cross-site scripting (XSS) vulnerability.

Solution: 
Install the latest version:

* If you use the 3.x branch, upgrade to Feed Block 3.0.2 [3].
* If you use the 2.x branch, upgrade to Feed Block 2.0.2 [4].

Reported By: 
* Marcus Johansson (marcus_johansson) [5]

Fixed By: 
* Greg Knaddison (greggles) [6] of the Drupal Security Team
* Mark Fullmer (mark_fullmer) [7]
* mmarler [8]

Coordinated By: 
* Bram Driesen (bramdriesen) [9] of the Drupal Security Team
* Greg Knaddison (greggles) [10] of the Drupal Security Team
* Juraj Nemec (poker10) [11] of the Drupal Security Team
* Jess (xjm) [12] of the Drupal Security Team
* Swan Kalata (akalata) [13] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [14]

[1] https://www.drupal.org/project/feed_block
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/feed_block/releases/3.0.2
[4] https://www.drupal.org/project/feed_block/releases/2.0.2
[5] https://www.drupal.org/u/marcus_johansson
[6] https://www.drupal.org/u/greggles
[7] https://www.drupal.org/u/mark_fullmer
[8] https://www.drupal.org/u/mmarler
[9] https://www.drupal.org/u/bramdriesen
[10] https://www.drupal.org/u/greggles
[11] https://www.drupal.org/u/poker10
[12] https://www.drupal.org/u/xjm
[13] https://www.drupal.org/u/akalata
[14] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3615545

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Feed Block - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-137, security-news, 09.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang