API Security Weekly: Issue #20

This week we look into vulnerabilities at Uber and Drupal, ICANN DNS security checklist, upcoming European IoT security standards, and more vulnerability stats from 2018.


This is the worst API vulnerability of the year so far. Drupal's RESTful Web Services (rest), JSON:API and other web services modules allow arbitrary remote code execution. The vulnerability caused by lack of input data sanitization. Attackers are already exploiting the vulnerability. If your site is on Drupal, upgrade and patch it ASAP.