VDB
KO

DRUPAL-CONTRIB-2026-113

Details

The Entity API module extends the Drupal core entity API to provide a unified way to deal with entities and their properties.

The module doesn't correctly apply access controls for JSON:API entity collection endpoints. This exposes an information disclosure vulnerability.

This vulnerability is mitigated by the fact that the JSON:API module must be enabled in combination with the Entity API module.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/entity
Introduced in: 0 Fixed in: 1.8.0

Upgrade drupal/entity to 1.8.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References