{"id":"DRUPAL-CONTRIB-2026-106","details":"This module integrates Drupal Commerce with the CyberSource payment gateway.\n\nThe module does not correctly verify the integrity of data returned by the payment provider. A timing attack could allow an attacker to trick the site into registering that payment has been received even if it hasn't.\n\nThis issue only affects the Secure Acceptance Hosted Checkout gateway integration.","aliases":["CVE-2026-81159"],"modified":"2026-08-26T22:41:58.654224Z","published":"2026-08-26T17:35:31Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-106"}],"affected":[{"package":{"name":"drupal/commerce_cybersource","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/commerce_cybersource?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.0"}],"database_specific":{"constraint":"\u003c1.10.0"}}],"database_specific":{"affected_versions":"\u003c1.10.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_cybersource/DRUPAL-CONTRIB-2026-106.json"}}],"schema_version":"1.9.0","credits":[{"name":"Brian Willows","contact":["https://www.drupal.org/u/brian-willows"]}]}