PT-2026-89238 · Packagist · Drupal/Csp Log

CVE-2026-87938

·

Published

2026-09-09

·

Updated

2026-09-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to an account with the Access CSP reports permission to exploit the SQL Injection.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-87938
DRUPAL-CONTRIB-2026-136

Affected Products

Drupal/Csp Log