DRUPAL-CONTRIB-2026-179

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_decoupled_checkout/DRUPAL-CONTRIB-2026-179.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2026-179
Aliases
  • CVE-2026-96378
Published
2026-09-23T17:06:19Z
Modified
2026-09-23T19:15:05Z
Summary
[none]
Details

This module enables REST endpoints for a decoupled Commerce experience which allow for remote order creation.

The module doesn't sufficiently sanitize order data passed into the order creation endpoint, which allows for potentially unsafe order properties to be set on an order.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/commerce_decoupled_checkout

Package

Name
drupal/commerce_decoupled_checkout
Purl
pkg:composer/drupal/commerce_decoupled_checkout?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.8.0
Database specific
Show details
{
    "constraint":  ">=1.0.0 <1.8.0"
}

Database specific

affected_versions
">=1.0.0 <1.8.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_decoupled_checkout/DRUPAL-CONTRIB-2026-179.json"