DRUPAL-CONTRIB-2026-104

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/blazy/DRUPAL-CONTRIB-2026-104.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-104
Aliases
  • CVE-2026-81165
Published
2026-08-26T17:33:51Z
Modified
2026-08-26T22:30:03.604065089Z
Summary
[none]
Details

This module enables users to display a field of a target entity through a Blazy Filter plugin shortcode.

The module does not consistently check entity view access. If a user has access to a Blazy-enabled text format, this allows them to render a field from an entity they are not permitted to view.

The issue is mitigated by the fact that the shortcode does not expose the entire entity. Only fields that the shortcode can render are vulnerable.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/blazy

Package

Name
drupal/blazy
Purl
pkg:composer/drupal/blazy?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.18
Database specific
Show details
{
    "constraint": "<3.0.18"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/blazy/DRUPAL-CONTRIB-2026-104.json"
affected_versions
"<3.0.18"