Feed/CVE-2023-26052
CVE-2023-26052LOWCVSS 3.7

Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions

Published Mar 2, 2023·Updated Jul 28, 2026

NVD Description

### Impact Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like infrastructure details in unauthenticated requests. Affected versions: Saleor ≥ 2.0.0 ### Workarounds None ### For more information If you have any questions or comments about this advisory: * Open a discussion at https://github.com/saleor/saleor/discussions * Email us at [hello@saleor.io](mailto:hello@saleor.io)

Affected Packages (1)

saleorPYPI
From 2.0.0
Fixed in 3.1.48

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free