CVE-2026-3216: Drupal Canvas Project Drupal Canvas

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue affects Drupal Canvas: from 0.0.0 before 1.1.1.

Affected products

Published 2026-03-25. Last modified 2026-06-17.