Answer in brief
CVE-2026-93650 records a Unknown severity vulnerability in Saleor throttling.py get_client_ip excessive authentication. The current sources do not mark it as known exploited. The current feed maps n/a/Saleor (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps n/a/Saleor (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| n/a/Saleorgeneric | 3.20.118 || 3.21.0 || 3.21.1 || 3.21.2 || 3.21.3 || 3.21.4 || 3.21.5 || 3.21.6 || 3.21.7 || 3.21.8 || 3.21.9 || 3.21.10 || 3.21.11 || 3.21.12 || 3.21.13 || 3.21.14 || 3.21.15 || 3.21.16 || 3.21.17 || 3.21.18 || 3.21.19 || 3.21.20 || 3.21.21 || 3.21.22 || 3.21.23 || 3.21.24 || 3.21.25 || 3.21.26 || 3.21.27 || 3.21.28 || 3.21.29 || 3.21.30 || 3.21.31 || 3.21.32 || 3.21.33 || 3.21.34 || 3.21.35 || 3.21.36 || 3.21.37 || 3.21.38 || 3.21.39 || 3.21.40 || 3.21.41 || 3.21.42 || 3.21.43 || 3.21.44 || 3.21.45 || 3.21.46 || 3.21.47 || 3.21.48 || 3.21.49 || 3.21.50 || 3.21.51 || 3.21.52 || 3.21.53 || 3.21.54 || 3.22.0 || 3.22.1 || 3.22.2 || 3.22.3 || 3.22.4 || 3.22.5 || 3.22.6 || 3.22.7 || 3.22.8 || 3.22.9 || 3.22.10 || 3.22.11 || 3.22.12 || 3.22.13 || 3.22.14 || 3.22.15 || 3.22.16 || 3.22.17 || 3.22.18 || 3.22.19 || 3.22.20 || 3.22.21 || 3.22.22 || 3.22.23 || 3.22.24 || 3.22.25 || 3.22.26 || 3.22.27 || 3.22.28 || 3.22.29 || 3.22.30 || 3.22.31 || 3.22.32 || 3.22.33 || 3.22.34 || 3.22.35 || 3.22.36 || 3.22.37 || 3.22.38 || 3.22.39 || 3.22.40 || 3.22.41 || 3.22.42 || 3.22.43 || 3.22.44 || 3.22.45 || 3.22.46 || 3.22.47 || 3.23.0 || 3.23.1 || 3.23.2 || 3.23.3 || 3.23.4 || 3.23.5 || 3.23.6 || 3.23.7 || 3.23.8 || 3.23.9 || 3.23.10 || 3.23.11 || 3.23.12 || 3.23.13 || 3.23.14 | Not reported |
Published upstream
Sep 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 18, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 18, 2026
A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of excessive authentication attempts. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been publicly disclosed and may be utilized. The projects own issue #19203 internal ticket admits "IP can be spoofed in most deployments" and that its REAL_IP_ENVIRON-type setting bypasses get_client_ip; fix (right-to-left RFC 7239 hop selection) proposed but still unmerged. The vendor explains within an email, that "[t]his is not a vulnerability, this is working at intended, Saleor expects XFF to be configured properly".
Quoted source text, attributed separately from HOL analysis.