← Back

CVE-2026-33756

nvd nist
Published: Apr 8, 2026Modified: Jul 24, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on the number of operations. This allowed an unauthenticated attacker to send a single HTTP request many operations (bypassing the per query complexity limit) to exhaust resources. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

Affected (6)

Products: Saleor: Saleor
1 product
Saleor
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Saleor
From 2.0.0 to 3.20.118
From 3.21.0 to 3.21.54
From 3.22.0 to 3.22.47
Version 3.23.0 alpha0
Version 3.23.0 alpha1
Version 3.23.0 alpha2

Timeline

No history available yet.