MEDIUM
saleor
CVE published 2026-04-08
CVE-2026-39851
The Saleor e-commerce platform has a vulnerability in its requestEmailChange mutation. From version 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the mutation reveals the existence of user-provided email addresses in error messages. This issue has been fixed in versions 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118. The vulnerability can be exploited by attackers to gather information about valid [truncated]