Visit Drupal NES Home Page

OpenID Connect Release Notes

1 version

Comprehensive release notes and changelog for OpenID Connect, including security patches, bug fixes, and feature updates across all supported versions.

Apr 14, 2026
Latest: 7.1.4
3 Patched Vulnerabilities
VEX Statements

April 2026

Full Version:
7.1.4+7.1.3:openid_connect

Notes

This is the initial NES release of the OpenID Connect module.

Changes

  • Security: Apply fix for CVE-2026-3531 by enforcing safer OpenID Connect prompt handling.
  • Security: Added patch for CVE-2026-3532 to prevent duplicate account creation by email case variation.
  • Security: Apply backport of CVE-2026-3531 by hardening user picture fetching from OpenID Connect providers.
  • Testing: Add additional tests.

Stay in the loop

~/herodevs-spring-framework-support

Open Source Support

When official support ends, we're just getting started.