CVE-2026-3216 | Canvas up to 1.1.0 on Drupal server-side request forgery (sa-contrib-2026-017)
A vulnerability was found in Canvas up to 1.1.0 on Drupal. It has been declared as critical. This issue affects some unknown processing. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-3216. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.