CVE-2026-39851

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/04/2026
Last modified:
20/04/2026

Description

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* 2.10.0 (including) 3.20.118 (excluding)
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* 3.21.0 (including) 3.21.54 (excluding)
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* 3.22.0 (including) 3.22.47 (excluding)
cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:saleor:saleor:3.23.0:alpha2:*:*:*:*:*:*