OpenID Connect / OAuth client
3 security fixes in one update. OpenID Connect / OAuth client fixed 3 separate security bugs this week: 2 access bypass, 1 server side request forgery. One update covers all of them. The most serious, SA-CONTRIB-2026-026, is explained here and the full list is at the end of the card.
A person who is blocked from logging in due to a server error might stay logged in at the external provider. Someone else using the same shared computer could then access the website as that person and see their private information. They could not change any information on the site.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate OpenID Connect / OAuth client to 8.x-1.5.
For developers: what the fix changed
The fix adds support for the `prompt` parameter in OpenID Connect authentication requests, defaulting to `login` in `src/Plugin/OpenIDConnectClientBase.php` to ensure users are explicitly prompted to authenticate by the Identity Provider. It also adds an update hook and requirements check in `openid_connect.install` to warn administrators if the prompt is misconfigured.
Also in this release The release also adds entity validation during user creation, improves profile picture handling, fixes a fatal error in the user login form, and adds a GitLab CI configuration and project logo.
.gitlab-ci.yml+60 −0config/schema/openid_connect.schema.yml+36 −0 fixlogo.png+0 −0openid_connect.install+51 −0 fixopenid_connect.module+7 −4openid_connect.services.yml+1 −1src/OpenIDConnect.php+170 −17src/Plugin/OpenIDConnectClientBase.php+31 −1 fix
- Moderately critical · Access bypass · SA-CONTRIB-2026-026
- Moderately critical · Server side request forgery, Information disclosure · SA-CONTRIB-2026-025
- Less critical · Access bypass · SA-CONTRIB-2026-027