Medium severity6.5NVD Advisory· Published Mar 2, 2023· Updated Jun 17, 2026
CVE-2023-26051
CVE-2023-26051
Description
Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like user email address in staff-authenticated requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
SaleorPyPI | >= 2.0.0, < 3.1.48 | 3.1.48 |
SaleorPyPI | >= 3.11.0, < 3.11.12 | 3.11.12 |
SaleorPyPI | >= 3.10.0, < 3.10.14 | 3.10.14 |
SaleorPyPI | >= 3.9.0, < 3.9.27 | 3.9.27 |
SaleorPyPI | >= 3.8.0, < 3.8.30 | 3.8.30 |
SaleorPyPI | >= 3.7.0, < 3.7.59 | 3.7.59 |
saleorPyPI | >= 2.0.0, < 3.1.48 | 3.1.48 |
saleorPyPI | >= 3.7.0, < 3.7.59 | 3.7.59 |
saleorPyPI | >= 3.8.0, < 3.8.30 | 3.8.30 |
saleorPyPI | >= 3.9.0, < 3.9.27 | 3.9.27 |
saleorPyPI | >= 3.10.0, < 3.10.14 | 3.10.14 |
saleorPyPI | >= 3.11.0, < 3.11.12 | 3.11.12 |
Affected products
3Patches
Vulnerability mechanics
References
11- github.com/saleor/saleor/commit/31bce881ccccf0d79a9b14ecb6ca3138d1edeec1nvdPatchWEB
- github.com/advisories/GHSA-r8qr-wwg3-2r85ghsaADVISORY
- github.com/saleor/saleor/security/advisories/GHSA-r8qr-wwg3-2r85nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-26051ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/saleor/PYSEC-2026-917.yamlghsaWEB
- github.com/saleor/saleor/releases/tag/3.1.48nvdRelease NotesWEB
- github.com/saleor/saleor/releases/tag/3.10.14nvdRelease NotesWEB
- github.com/saleor/saleor/releases/tag/3.11.12nvdRelease NotesWEB
- github.com/saleor/saleor/releases/tag/3.7.59nvdRelease NotesWEB
- github.com/saleor/saleor/releases/tag/3.8.30nvdRelease NotesWEB
- github.com/saleor/saleor/releases/tag/3.9.27nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.