PT-2026-95596 · Git · Saleor

·

CVE-2026-93650

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Saleor versions prior to 3.20.119 Saleor versions prior to 3.21.55 Saleor versions prior to 3.22.48 Saleor versions prior to 3.23.15
Description An issue exists in the get client ip() function within the saleor/account/throttling.py file. A remote attacker can manipulate the request to spoof the client IP address, which may lead to the improper restriction of excessive authentication attempts. This occurs because the REAL IP ENVIRON setting can bypass the get client ip() function, and the system may not correctly handle X-Forwarded-For (XFF) headers, which are used to identify the originating IP address of a client connecting to a web server through an HTTP proxy.
Recommendations Ensure that X-Forwarded-For (XFF) headers are configured properly in the deployment environment to prevent IP spoofing. As a temporary mitigation, restrict or carefully monitor the use of the get client ip() function in saleor/account/throttling.py until a formal patch is merged.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93650

Affected Products

Saleor