Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189
  • Date: Wed, 23 Sep 2026 17:22:39 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=iF4rXtgk; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=GW4rc8ye; arc=none smtp.remote-ip=54.240.27.123
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 0A165446F7
  • Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 1B79980848
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790187449; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=DOZ2rJAHh0b7EoVlYNRrO4LGBoZQRvEiVWJUWtqTK2E=; b=ikz57PpZMF2D7klCe3uqqYTIRPKdAQMiNvRnAmsfM2dtCI5wXlRDlxjcCUnpD2HG49E+ 0nXNNGF5Q8gikMu1A6KBGSzrcA8l/YiUIlctRj9qZiCSHyYQBL/IcJlBeh0ZrXYo7tMuS w6t4CPm3IOIg4ydk89jqRF16cPmkAGrfXWS2HAjZX1A4G3iCNwdVbUlAKp5LAi3AKp36m 65xKkPOxSIEGUm79ZLQ0TRz3eIkpuBpKNOHtslxeo6hxLeZUT058aNaKArtDJxzWM/90y A7vyL4EF47hGdVl4RVr2E3hvGj/CPLrI+Z1yTJTD3L6fjxUXTMqq8IDwIzH3XZKFfGg==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184161; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=+/ycMnegrFEtLqtuSE1Ddp2hkfEgcKR/zrf/SZfp/mQ=; b=tQXnwviJGupx7QorlWQMJu7tOaNCzybdGSMBualukq7Cue2+QVGD9ULg/jBqgXXJfgNW sKy58LFN87ZrRhHLObNDENDPz2IcKiPFeF3p+HJaQ/KemQV/nRAPfRdkI8K/rSMHrp2Kg BeOkdzRhDNe4djkOsyfYOFHU7Iss3b9x9r2leunNY8O2CZwj8/2UILmpDV5L0IhWsL0PR 4iR8YTVq+HDgh0ypTAOZ01tlJTz7QWn31Gj+ClKCpnEBadz7UhQzxJDZP2u8sBZV4PzDm p295JQX0dUTCEHTkVMLE4NK1d6Qet6lomoFia5PUy1Sg7czdECwfbE82tZCXc83FFTQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790187449; b=P4BfYKyblHSHovUhFHhQu/AFunDvP5GuvF+pWsAxrWhS5Y9HesoprUB1a/uAlphhSydk BxB0c+4kuTST//BU+yAoaiIUvZ32chn+89YUB3Ai7AIXGTmIqvKBoQzDqYxBtMn+6tDK0 4OFHuo3SB66RN7ejZQtza9nEQEUW0ejHEIvlYsR0hLOIX36gh6JSRCgI+hp9chNNf2vD3 E/i/w8vw0gNfvzeVXk3niplFl5hg46xBzFWp/CR6+qOo5+qXckGxyG66ODhGlYTluXhYt ItUY7Uxq/ddh3AKf/zzXgz2E7/zFEk5Bw+kHIt7Pw5ttwZnKt0i9Xr9njEZmrfXcMiA==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790184161; b=fQSJLgeqVEy1oQcxlTVg4vr3iKRPWIDzeqhPwQRJ7ZoD0Z28V0hGwAqJPq77AouaYcCw 1sGbmwHZjhbS9i9xRjf/MmFr0b6j1xBr9YcX1Xk/cy9/DtzxyGC69ISKVjFqGNZcOJp0x J6caMijFQywhiYTp81Tastx1HPLWpUXRiHeXy3vsxA1mIN7XKca7Sc8UbGnrQcuNljdHY x7n0jEJkTMekH+0Wa/fori6RswTyr4JF8i3+Dbki72X9O1P92TghcPLBbf0BDisfuN5h0 PGd2O44M9W2q344sqpNzJhIg/iISaZzqrMmcSKAVMHK0t0x6OFPW04xNJy/vwhlDnKg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/XKQ7GSPRJNLW5E6ZBLMUUDZ6U7HBO2GP/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b="JuI/TiJW"; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=iF4rXtgk; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=GW4rc8ye; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-189

Project: CSS Usage Analyzer [1]
Project machine name: css_usage_analyzer
Date: 2026-September-23
Security risk: *Moderately critical* 13 ∕ 25
AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Improper access control

Affected versions: >=1.0.0 <1.0.2
CVE IDs: CVE-2026-96380
Description: 
This module lets a frontend scanner post CSS-usage measurements to the site
so admin reports can show real-page statistics.

This module doesn't sufficiently protect the /css-usage-analyzer/save
endpoint against forged or repeated submissions.

Solution: 
Install the latest version:

* Upgrade to CSS Usage Analyzer 1.0.2 [3].

Reported By: 
* Marcus Johansson (marcus_johansson) [4]

Fixed By: 
* Greg Knaddison (greggles) [5] of the Drupal Security Team
* Marcus Johansson (marcus_johansson) [6]
* Zeeshaan khann (zeeshan_khan) [7]

Coordinated By: 
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Juraj Nemec (poker10) [9] of the Drupal Security Team
* Jess (xjm) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/css_usage_analyzer
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/css_usage_analyzer/releases/1.0.2
[4] https://www.drupal.org/u/marcus_johansson
[5] https://www.drupal.org/u/greggles
[6] https://www.drupal.org/u/marcus_johansson
[7] https://www.drupal.org/u/zeeshan_khan
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/poker10
[10] https://www.drupal.org/u/xjm
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3622542

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] CSS Usage Analyzer - Moderately critical - Improper access control - SA-CONTRIB-2026-189, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang