#JSONAPI
Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127 Read post
September 2, 2026 at 5:17 PM
#Drupal security advisory: Jsonapi Role Access - Critical - Access bypass - SA-CONTRIB-2026-127 (2026-09-02) #PHP. See https://www.drupal.org/sa-contrib-2026-127
September 2, 2026 at 5:00 PM
📦 serhiikamolov/laravel-jsonapi v4.4.0

A set of interfaces and classes to facilitate the construction of an efficient Json Api application with the Laravel framework.

🔗 https://github.com/serhiikamolov/laravel-jsonapi
August 31, 2026 at 7:58 PM
I took over a bit of security maintenance for #Drupal entity API module.

If you use it with JSONAPI you should upgrade.

Thanks @berdir for the collaboration 😍

drupal.org/sa-contrib-2026-113…
August 26, 2026 at 6:30 PM
📦 alsvanzelf/jsonapi v3.0.2

Human-friendly library to implement JSON:API without needing to know the specification.

🔗 https://github.com/lode/jsonapi
August 22, 2026 at 8:01 AM
JSON:API Views 8.x-1.2 fixes cache metadata, route-build performance, preview URLs, numeric bundle routing and OpenAPI discovery. A stable contrib update for decoupled Drupal using Views over JSON:API.
##Drupal #JSONAPI #DecoupledDrupal #DrupalViews

https://bit.ly/4zeaoca
August 13, 2026 at 2:34 PM
nrcmedia har nettopp åpnet repoet nrcmedia/jsonapi-serializer: https://github.com/nrcmedia/jsonapi-serializer

Et rammeverksuavhengig bibliotek for Node.js som brukes til å serialisere data til JSON API
July 7, 2026 at 1:29 PM
Drupal Security Team published eight advisories on 17 June: five for core, three for contrib.

Core fixes cover JSON:API, oEmbed, image upload validation, and deserialization risks.

https://bit.ly/4oBXorV
##Drupal #DrupalSecurity #JSONAPI #DrupalCore
June 18, 2026 at 2:45 PM
F5 Labs reports scanner activity targeting Drupal CVE-2026-9082 after disclosure.

Observed probes focused on JSON:API node endpoints and used blind SQL injection patterns, with defensive advice centred on logs and access review.

https://bit.ly/4gobUS4
##Drupal #Cybersecurity #JSONAPI
F5 Labs Details Drupal CVE-2026-9082 Scanning Patterns
F5 Labs’ Sensor Intel report adds sensor-level evidence to the CVE-2026-9082 response, documenting how scanners probed Drupal JSON:API endpoints after disclosure rather than revisiting the advisory itself. Its useful contribution is the traffic patte...
bit.ly
June 16, 2026 at 2:03 PM
DrupalRX’s Darrell Green examines why JSON:API responses can slow down headless Drupal projects.

The article highlights payload size, broad includes, deep relationships, caching gaps, serialisation work, and frontend request behaviour.

https://bit.ly/4ghQqGm
##JSONAPI #HeadlessDrupal #Performance
DrupalRX Article Examines JSON:API Performance Issues in Headless Drupal
DrupalRX has published a technical article on common causes of slow JSON:API responses in headless Drupal projects. The post argues that teams should examine payload size, includes, relationship depth, caching, serialization costs, and frontend reque...
bit.ly
June 10, 2026 at 4:48 PM
📦 aimeos/pagible-jsonapi 0.11.1

Pagible CMS - JSON:API server

🔗 https://github.com/aimeos/pagible-jsonapi
June 5, 2026 at 6:31 PM
🔒 API Platform CVE-2026-49858: JSON:API & HAL normalizers cached components across users on long-running runtimes (FrankenPHP, RoadRunner, Swoole).

Patched in 4.1.29 / 4.2.25 / 4.3.8 — upgrade now.

github.com/api-platform...
Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
### Impact `#[ApiProperty(security: ...)]` is evaluated per request to decide whether a property is exposed. The `componentsCache` arrays in `ApiPlatform\JsonApi\Serializer\ItemNormalizer` and `Ap...
github.com
June 4, 2026 at 12:08 PM
📦 serhiikamolov/laravel-jsonapi v4.2.1

A set of interfaces and classes to facilitate the construction of an efficient Json Api application with the Laravel framework.

🔗 https://github.com/serhiikamolov/laravel-jsonapi
May 31, 2026 at 6:18 PM
📦 serhiikamolov/laravel-jsonapi v4.3.1

A set of interfaces and classes to facilitate the construction of an efficient Json Api application with the Laravel framework.

🔗 https://github.com/serhiikamolov/laravel-jsonapi
May 31, 2026 at 6:17 PM
🚨 In this week’s newsletter, we cover CVE-2026-9082, a Drupal JSON: API SQL injection vulnerability now under active exploitation.

We break down how attackers are targeting exposed /jsonapi/ endpoints and what defenders should do next.

👉 www.crowdsec.net/vulntracking...
May 25, 2026 at 12:44 PM
Where do you stand on jsonapi these days?
May 18, 2026 at 8:50 PM
New #Drupal module: Jsonapi SDC (2026-05-07) #PHP. See https://www.drupal.org/project/jsonapi_sdc
May 7, 2026 at 1:00 PM
📦 aimeos/pagible-jsonapi 0.10.2

Pagible CMS - JSON:API server

🔗 https://github.com/aimeos/pagible-jsonapi
April 26, 2026 at 8:20 AM
Drupal Canvas currently limits Views to block-only integration with minimal configuration. A workaround using HTMX + JSON:API restores dynamic behavior.

Read more: https://bit.ly/3Qt3ONb
##Drupal #DrupalCanvas #HTMX #JSONAPI
Drupal Canvas Views Limitations and Workaround with HTMX Explained
A blog post shows how developers handle dynamic content in Drupal Canvas using HTMX and code components due to current Views limitations.
bit.ly
April 24, 2026 at 1:26 PM
📦 alsvanzelf/jsonapi v3.0.1

Human-friendly library to implement JSON:API without needing to know the specification.

🔗 https://github.com/lode/jsonapi
April 20, 2026 at 7:20 PM
📦 demos-europe/edt-jsonapi 0.27.0

Expose Doctrine entities as JSON:API resources.

🔗 https://github.com/demos-europe/edt-jsonapi
April 17, 2026 at 1:23 PM
📦 aimeos/pagible-jsonapi 0.10.0

Pagible CMS - JSON:API server

🔗 https://github.com/aimeos/pagible-jsonapi
April 16, 2026 at 12:12 PM
Laravel 13 Ships JSON:API Resources. Your API Just Got a Spec.
via Medium Programming

https://flarestart.com/article/laravel-13-ships-jsonapi-resources-your-api-just-got-a-spec-20260328
#DevNews #WebDevelopment
Laravel 13 Ships JSON:API Resources. Your API Just Got a Spec.
JsonApiResource handles resource serialization, relationship inclusion, sparse fieldsets, links, meta, and the correct Content-Type header… Continue reading on Medium »
flarestart.com
March 28, 2026 at 2:40 AM
📌 CVE-2026-33286 - Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary met... https://www.cyberhub.blog/cves/CVE-2026-33286
CVE-2026-33286
Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary rela
www.cyberhub.blog
March 25, 2026 at 6:00 PM
CRITICAL: Graphiti (<1.10.2) vulnerability lets unauthenticated attackers execute arbitrary public methods via JSONAPI. Patch to 1.10.2+ or restrict access now! https://radar.offseq.com/threat/cve-2026-33286-cwe-913-improper-control-of-dynamic-fd76d864 #OffSeq #Graphiti #AppSec
CVE-2026-33286: CWE-913: Improper Control of Dynamically-Managed Code Resources
Graphiti is a Ruby framework that exposes models via a JSON:API-compliant interface. Versions before 1.10.2 contain a critical vulnerability (CVE-2026-33286) classified under CWE-913 (Improper Control of Dynamically-Managed Code Resources).
radar.offseq.com
March 24, 2026 at 3:00 AM