—
DRUPAL-CONTRIB-2026-136
Details
The CSP Log module enhances any module that adds the CSP header to a site, by providing a reporting endpoint, custom storage, and aggregated reports that can be used to trace issues or adapt the CSP headers.
The module did not sufficiently sanitize user-supplied values used in database queries, resulting in an SQL injection vulnerability.
This vulnerability is mitigated by the fact that an attacker needs access to an account with the *Access CSP reports* permission to exploit the SQL Injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/csp_log
Introduced in:
0Fixed in: 1.0.2Upgrade drupal/csp_log to 1.0.2 or newer (ecosystem packagist:https://packages.drupal.org/8).