DRUPAL-CONTRIB-2026-176

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/cloud/DRUPAL-CONTRIB-2026-176.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-176
Aliases
  • CVE-2026-96375
Published
2026-09-23T16:50:15Z
Modified
2026-09-23T19:15:04Z
Summary
[none]
Details

The Cloud module enables users to manage cloud infrastructure through Drupal.

The Kubernetes and VMware integrations do not properly validate TLS certificates when connecting to remote API endpoints. An attacker who can intercept these connections may obtain secret tokens or other credentials, potentially allowing unauthorized access to the connected infrastructure.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/cloud

Package

Name
drupal/cloud
Purl
pkg:composer/drupal/cloud?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
7.0.1
Database specific
Show details
{
    "constraint":  "<7.0.1"
}

Database specific

affected_versions
"<7.0.1"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/cloud/DRUPAL-CONTRIB-2026-176.json"