CVE-2026-28288
Dify has a user enumeration issue
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.
| CWE | CWE-204 |
| Vendor | langgenius |
| Product | dify |
| Published | Feb 27, 2026 |
| Last Updated | Feb 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for langgenius dify
Be the first to know when new unknown vulnerabilities affecting langgenius dify are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
langgenius / dify
< 1.9.0