Description
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
Published: 2026-09-18
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass for Brute Force Attacks
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the get_client_ip function of Saleor’s throttling.py. The function fails to properly restrict repeated authentication attempts because the IP address used to enforce throttling can be spoofed, especially under most deployments that rely on the XFF header. This allows an attacker to perform a brute‑force login attempt from a single temporary address that is not correctly recorded, thereby bypassing the intended rate‑limit and potentially compromising user accounts. While the vendor has framed the behavior as intended with a correctly configured XFF, the absence of proper validation introduces a real security risk.

Affected Systems

Saleor versions up to 3.20.118, 3.21.54, 3.22.47, and 3.23.14 are affected. The issue is implemented in the saleor/account/throttling.py module of the Saleor open‑source e‑commerce framework.

Risk and Exploitability

The CVSS score of 6.3 classifies the weakness as moderate, but the EPSS score is below 1 percent, indicating a very low probability that the vulnerability is actively exploited at this time. The issue is not currently listed in CISA’s KEV catalog and is reported to be exploitable remotely, yet the exploit requires high technical complexity and is considered difficult to execute. Attackers would need to manipulate the XFF header or otherwise spoof the client IP to avoid the throttling logic, a scenario typically possible only in environments with misconfigured proxies or where IP spoofing is permitted.

Generated by OpenCVE AI on September 19, 2026 at 16:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Saleor to the latest release that incorporates the get_client_ip patch
  • If upgrading is not immediately possible, disable or limit the use of the XFF header by operating behind a trusted reverse proxy that strips or validates forwarded‑for values
  • Apply network‑level filtering to block IP spoofing or enforce strict source IP verification before the application receives requests
  • Mitigate at the application level by replacing IP‑based throttling with account‑based or credential‑based throttling so that repeated login attempts on a single account are limited regardless of source IP

Generated by OpenCVE AI on September 19, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
Title Saleor throttling.py get_client_ip excessive authentication
First Time appeared Saleor
Saleor saleor
Weaknesses CWE-307
CWE-799
CPEs cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
Vendors & Products Saleor
Saleor saleor
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T19:47:52.282Z

Reserved: 2026-09-18T13:07:36.010Z

Link: CVE-2026-93650

cve-icon Vulnrichment

Updated: 2026-09-18T19:47:49.150Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T19:17:24.973

Modified: 2026-09-18T20:17:33.177

Link: CVE-2026-93650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:45:17Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts

  • CWE-799

    Improper Control of Interaction Frequency