Skip to content

Saleor

v3.21.62 Security

This release includes 6 security fixes for security teams reviewing exposed deployments.

Published 23d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 6 known CVEs

Topics

cart checkout commerce composable e-commerce ecommerce
+12 more
graphql headless headless-commerce multichannel oms order-management payments pim python shop shopping-cart store

Affected surfaces

auth deps rce_ssrf

Summary

AI summary

Security updates: Pillow, pyasn1, Pygments, requests, authlib, and cryptography patches address multiple vulnerabilities.

Full changelog

What's Changed

Upgrade 7 dependencies to latest patches by @NyanKiyoshi in https://github.com/saleor/saleor/pull/19402:

  • Upgraded pillow to v12.3.0 which fixes multiple out-of-bounds writes & reads, as well a denial of services vulnerabilities. Full details: https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html#security
  • Upgraded pyasn1 to v0.6.3 which fixes CVE-2026-30922, "Fixes Denial of Service in pyasn1 via Unbounded Recursion"
  • Upgraded Pygments to v2.20.0 which fixes CVE-2026-4539, "Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching"
  • Upgraded requests to v2.34.2 which fixes CVE-2026-25645, "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function"
  • Upgraded authlib to v1.7.2 which fixes:
    • CVE-2026-44681, "Open Redirect in Authlib OIDC Implicit/Hybrid Authorization"
    • CVE-2026-41479, "Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type"
  • Upgraded cryptography to v49.0.0 which applies latest OpenSSL fixes

Full Changelog: https://github.com/saleor/saleor/compare/3.21.61...3.21.62

Security Fixes

  • CVE-2026-30922 — pyasn1 denial of service via unbounded recursion
  • CVE-2026-4539 — Pygments regular expression denial of service (ReDoS)
  • CVE-2026-25645 — requests insecure temp file reuse in extract_zipped_paths()
  • CVE-2026-44681 — authlib OIDC implicit/hybrid open redirect
  • CVE-2026-41479 — authlib OAuth 2.0 open redirect via unsupported response_type
  • Pillow v12.3.0 fixes multiple out‑of‑bounds reads/writes and denial‑of‑service issues

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Saleor

Get notified when new releases ship.

Sign up free

About Saleor

Django based open-sourced e-commerce storefront.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]