I've godt a message from my host:
Our automated vulnerability scanner has detected outdated software with known security vulnerabilities in the Pro Suite installation for cbmsupport.dk.
The vulnerabilities have been automatically patched, so the issue has already been mitigated.

It is still recommended to update any CMS components, themes, and plugins on the installation to their latest versions to ensure a permanent fix.

The affected file is:
/var/www/cbmsupport.dk/kb10/web/core/lib/Drupal/Core/Entity/Query/Sql/pgsql/Condition.php
Drupal core — Highly critical — SQL injection — SA‑CORE‑2026‑004"

Comments

uv516 created an issue. See original summary.

cilefen’s picture

Title: o Drupal core - Highly critical - SQL injection - SA-CORE-2026-004 » Hosting company says SA-CORE-2026-004 is unpatched
Component: sqlite db driver » postgresql db driver
daffie’s picture

Status: Active » Closed (works as designed)

When the big get fixed by patching, the software version does not get updated. The check on software with vulnerabilities is by version, no the actual code. Run "composer update" to fix the warning message.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

mcdruid’s picture

Unpublishing this issue for now; will discuss further in a private security issue (where we'll add participants from this public issue).

mcdruid’s picture

re-publishing; the issue outlined in my previous comment is being handled in a public followup: https://www.drupal.org/project/drupal/issues/3614837