No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly". | |
| Title | Saleor throttling.py get_client_ip excessive authentication | |
| First Time appeared |
Saleor
Saleor saleor |
|
| Weaknesses | CWE-307 CWE-799 |
|
| CPEs | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Saleor
Saleor saleor |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T19:47:52.282Z
Reserved: 2026-09-18T13:07:36.010Z
Link: CVE-2026-93650
Updated: 2026-09-18T19:47:49.150Z
Status : Deferred
Published: 2026-09-18T19:17:24.973
Modified: 2026-09-18T20:17:33.177
Link: CVE-2026-93650
No data.
OpenCVE Enrichment
No data.