Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:* cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:* cpe:2.3:a:saleor:saleor:3.23.0:alpha2:*:*:*:*:*:* |
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saleor
Saleor saleor |
|
| Vendors & Products |
Saleor
Saleor saleor |
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query batching by submitting multiple GraphQL operations in a single HTTP request as a JSON array but wasn't enforcing any upper limit on the number of operations. This allowed an unauthenticated attacker to send a single HTTP request many operations (bypassing the per query complexity limit) to exhaust resources. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118. | |
| Title | Saleor Affected by Denial of Service via Unbounded GraphQL Query Batching | |
| Weaknesses | CWE-770 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T18:42:28.521Z
Reserved: 2026-03-23T18:30:14.125Z
Link: CVE-2026-33756
Updated: 2026-04-08T18:42:22.931Z
Status : Analyzed
Published: 2026-04-08T18:26:00.700
Modified: 2026-04-20T20:04:43.593
Link: CVE-2026-33756
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:38:54Z