๐Ÿ” CVE Alert

CVE-2026-93650

LOW 3.7

Saleor throttling.py get_client_ip excessive authentication

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".

CWE CWE-307 CWE-799
Vendor n/a
Product saleor
Published Sep 18, 2026
Last Updated Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for n/a saleor

Be the first to know when new low vulnerabilities affecting n/a saleor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / Saleor
3.20.118 3.21.0 3.21.1 3.21.2 3.21.3 3.21.4 3.21.5 3.21.6 3.21.7 3.21.8 3.21.9 3.21.10 3.21.11 3.21.12 3.21.13 3.21.14 3.21.15 3.21.16 3.21.17 3.21.18 3.21.19 3.21.20 3.21.21 3.21.22 3.21.23 3.21.24 3.21.25 3.21.26 3.21.27 3.21.28 3.21.29 3.21.30 3.21.31 3.21.32 3.21.33 3.21.34 3.21.35 3.21.36 3.21.37 3.21.38 3.21.39 3.21.40 3.21.41 3.21.42 3.21.43 3.21.44 3.21.45 3.21.46 3.21.47 3.21.48 3.21.49 3.21.50 3.21.51 3.21.52 3.21.53 3.21.54 3.22.0 3.22.1 3.22.2 3.22.3 3.22.4 3.22.5 3.22.6 3.22.7 3.22.8 3.22.9 3.22.10 3.22.11 3.22.12 3.22.13 3.22.14 3.22.15 3.22.16 3.22.17 3.22.18 3.22.19 3.22.20 3.22.21 3.22.22 3.22.23 3.22.24 3.22.25 3.22.26 3.22.27 3.22.28 3.22.29 3.22.30 3.22.31 3.22.32 3.22.33 3.22.34 3.22.35 3.22.36 3.22.37 3.22.38 3.22.39 3.22.40 3.22.41 3.22.42 3.22.43 3.22.44 3.22.45 3.22.46 3.22.47 3.23.0 3.23.1 3.23.2 3.23.3 3.23.4 3.23.5 3.23.6 3.23.7 3.23.8 3.23.9 3.23.10 3.23.11 3.23.12 3.23.13 3.23.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/407477 vuldb.com: https://vuldb.com/vuln/407477/cti vuldb.com: https://vuldb.com/cve/CVE-2026-93650 vuldb.com: https://vuldb.com/submit/933655 github.com: https://github.com/zast-ai/vulnerability-reports/blob/main/saleor/bruteforce.md github.com: https://github.com/saleor/saleor/issues/19203 github.com: https://github.com/saleor/saleor/

Credits

๐Ÿ” ZAST.AI (VulDB User) VulDB CNA Team