Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93650— Saleor throttling.py get_client_ip excessive authentication

Quick assessment

Affected
n/a Saleor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authenticati

CVSS 3.7 · Low

Affected Version Matrix 119

VendorProduct Version RangeStatus
n/a Saleor 3.20.118 affected
3.21.0 affected
3.21.1 affected
3.21.2 affected
3.21.3 affected
3.21.4 affected
3.21.5 affected
3.21.6 affected
… +111 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93650

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Saleor throttling.py get_client_ip excessive authentication
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
过多认证尝试的限制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Saleor 3.20.118 cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-93650

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93650

登录查看更多情报信息。

Other References for CVE-2026-93650 (3)

Same Patch Batch · n/a · 2026-09-18 · 8 CVEs total

CVE-2026-93331 7.3 HIGH GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds
CVE-2026-93506 6.3 MEDIUM SveltyCMS File Upload Endpoint upload-media server-side request forgery
CVE-2026-93504 6.3 MEDIUM SveltyCMS User Attribute Update Endpoint +server.ts access control
CVE-2026-93505 3.5 LOW SveltyCMS SVG Media Upload media-service.server.ts cross site scripting
CVE-2026-88623 NUUO NVR 2.0.0 任意文件读取漏洞
CVE-2026-88622 NUUO NVR 2.0.0命令注入漏洞
CVE-2026-79294 Kimi 2026-07-18版 HTML预览XSS漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-93650

No comments yet


Leave a comment