—
DRUPAL-CONTRIB-2026-106
Details
This module integrates Drupal Commerce with the CyberSource payment gateway.
The module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.
This issue only affects the Secure Acceptance Hosted Checkout gateway integration.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/commerce_cybersource
Introduced in:
0 Fixed in: 1.10.0 Upgrade drupal/commerce_cybersource to 1.10.0 or newer (ecosystem packagist:https://packages.drupal.org/8).