VDB
KO

DRUPAL-CONTRIB-2026-058

Details

This module enables you to take payments through the Global Payments / Realex Hosted Payment Page (HPP), either via a lightbox iframe or via a full-page redirect.

When the gateway is configured with the **redirect** payment method, the module doesn't sufficiently verify the authenticity of the payment response returned by Global Payments.

The **lightbox** payment method validates the signature and is not affected, so sites that use the lightbox payment method are not affected.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/commerce_realex
Introduced in: 0 Fixed in: 3.0.2

Upgrade drupal/commerce_realex to 3.0.2 or newer (ecosystem packagist:https://packages.drupal.org/8).

References