Date iCal - Critical - Information disclosure - SA-CONTRIB-2026-037
Project: Date iCalDate: 2026-May-13Security risk: Critical 17 ∕ 25 AC:None/A:None/CI:All/II:None/E:Theoretical/TD:AllVulnerability: Information disclosureAffected versions: <4.0.15CVE IDs: CVE-2026-8495Description: This module enables you to export entity date fields as iCal feeds.
The module doesn't sufficiently check entity or field access or sanitize user inputs when generating iCal feeds.
This vulnerability is not mitigated by any permission, the routes are accessible to all anonymous users with no configuration required.Solution: Install the latest version:
- If you use the Date iCal module for Drupal 10/11, upgrade to Date iCal 4.0.15
Reported By:
- Drew Webber (mcdruid) of the Drupal Security Team
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team

