—
DRUPAL-CONTRIB-2026-113
Details
The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.
The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.
This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8 / drupal/entity
Introduced in:
0 Fixed in: 1.8.0 Upgrade drupal/entity to 1.8.0 or newer (ecosystem packagist:https://packages.drupal.org/8).