Description
Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenID Connect / OAuth client allows Server Side Request Forgery.This issue affects OpenID Connect / OAuth client: from 0.0.0 before 1.5.0.
Problem types
CWE-918 Server-Side Request Forgery (SSRF)
Product status
0.0.0 (semver) before 1.5.0
Credits
Drew Webber (mcdruid)
Drew Webber (mcdruid)
Philip Frilling (pfrilling)
Damien McKenna (damienmckenna)
Greg Knaddison (greggles)
Drew Webber (mcdruid)
Juraj Nemec (poker10)
References
www.drupal.org/sa-contrib-2026-025