CVE-2026-35401

EUVD-2026-20532
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
saleorsaleor
2.0.0 ≤
𝑥
< 3.20.118
saleorsaleor
3.21.0 ≤
𝑥
< 3.21.54
saleorsaleor
3.22.0 ≤
𝑥
< 3.22.47
saleorsaleor
3.23.0:alpha0
saleorsaleor
3.23.0:alpha1
saleorsaleor
3.23.0:alpha2
𝑥
= Vulnerable software versions