DRUPAL-CONTRIB-2026-136
Dashboard / Vulnerabilities / DRUPAL-CONTRIB-2026-136
Summary:
Details: The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers. The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability. This vulnerability is mitigated by the fact that an attacker needs access to an account with the *Access CSP reports* permission to exploit the SQL Injection.
References: https://www.drupal.org/sa-contrib-2026-136
Affected packages
Package
Name: drupal/csp_log
Purl: pkg:composer/drupal/csp_log?repository_url=https:%2F%2Fpackages.drupal.org%2F8
Affected ranges
Type: ECOSYSTEM
Events:
