Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly". | |
| Title | Saleor throttling.py get_client_ip excessive authentication | |
| First Time appeared |
Saleor
Saleor saleor |
|
| Weaknesses | CWE-307 CWE-799 |
|
| CPEs | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Saleor
Saleor saleor |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-18T19:47:52.282Z
Reserved: 2026-09-18T13:07:36.010Z
Link: CVE-2026-93650
Updated: 2026-09-18T19:47:49.150Z
Status : Deferred
Published: 2026-09-18T19:17:24.973
Modified: 2026-09-18T20:17:33.177
Link: CVE-2026-93650
No data.
OpenCVE Enrichment
No data.