
CVE-2026-3217 SAML SSO - Service Provider - Critical - Cross-site scripting - SA-CONTRIB-2026-018 | Drupal .org https://www.drupal.org/sa-contrib-2026-018
Post summary
Drupal SAML SSO service provider is vulnerable to a critical cross‑site scripting flaw (CVE‑2026‑3217); the advisory SA‑CONTRIB‑2026‑018 provides patch details.


