Publicly disclosedModerately critical · 10/25
Drupal OpenAI Provider
SA-CONTRIB-2026-053
- Class
- Server-Side Request Forgery
- Role
- Reporter / Fix contributor
- Fixed versions
- 1.1.1 / 1.2.2
- Credit
- Kuniyoshi Noguchi (kuninogu)
$ cat advisories.tsv
Public vulnerability disclosures, CVE/JVN entries, and vendor acknowledgements.
Verified against primary sources
Every row links directly to a public record from the vendor, maintainer, or vulnerability coordinator.
SA-CONTRIB-2026-053
SA-CONTRIB-2026-055
SA-CONTRIB-2026-056
GHSA-7hrw-592w-9wh2
S2-074
SVD-2026-0808
| Advisory ID | Product | Severity | Class | Role | Fixed versions | JVN | Detection / analysis | Credit |
|---|---|---|---|---|---|---|---|---|
CVE-2026-13233SA-CONTRIB-2026-053 | Drupal OpenAI Provider | Moderately critical · 10/25 | Server-Side Request Forgery | Reporter / Fix contributor | 1.1.1 / 1.2.2 | — | — | Kuniyoshi Noguchi (kuninogu) |
CVE-2026-13235SA-CONTRIB-2026-055 | Drupal AI | Moderately critical · 10/25 | Access Bypass | Reporter | 1.2.17 / 1.3.8 / 1.4.3 | — | — | Kuniyoshi Noguchi (kuninogu) |
CVE-2026-13236SA-CONTRIB-2026-056 | Drupal AI Agents | Less critical · 9/25 · JVN CVSS 4.0 7.1 | Access Bypass | Reporter / Fix contributor | 1.1.4 / 1.2.5 / 1.3.1 | JVN#20592637 | View → | Kuniyoshi Noguchi (kuninogu) |
CVE-2026-15631GHSA-7hrw-592w-9wh2 | @fastify/http-proxy | High · CVSS 8.7 | WebSocket Path Traversal | Reporter | 11.6.0 | — | — | KuniNogu |
CVE-2026-73635S2-074 | Apache Struts | Moderate · JVN CVSS 4.0 8.7 | Uncontrolled Resource Consumption / DoS | Reporter | 6.11.0 / 7.3.0 | JVN#08517956 | View → | Kuniyoshi Noguchi (野口 晋義), (@KuniNogu) |
CVE-2026-76404SVD-2026-0808 | Splunk MCP Server app | Critical · CVSS 9.1 | Unsafe Deserialization / RCE | Reporter | 1.2.1 | — | View → | Kuniyoshi Noguchi (KuniNogu) |
| Redmine | High | OAuth Scope Enforcement Bypass | Official credit | 6.1.3 | — | — | Kuniyoshi Noguchi (野口晋義), Mitsui Bussan Secure Directions, Inc. |
Every row links directly to a public record from the vendor, maintainer, or vulnerability coordinator.