This release includes 6 security fixes for security teams reviewing exposed deployments.
Published 23d
Productivity & Wikis
✓ No known CVEs patched
This release patches 6 known CVEs
Topics
cart
checkout
commerce
composable
e-commerce
ecommerce
+12 more
graphql
headless
headless-commerce
multichannel
oms
order-management
payments
pim
python
shop
shopping-cart
store
Affected surfaces
auth
deps
rce_ssrf
Summary
AI summarySecurity updates: Pillow, pyasn1, Pygments, requests, authlib, and cryptography patches address multiple vulnerabilities.
Full changelog
What's Changed
Upgrade 7 dependencies to latest patches by @NyanKiyoshi in https://github.com/saleor/saleor/pull/19402:
- Upgraded
pillowto v12.3.0 which fixes multiple out-of-bounds writes & reads, as well a denial of services vulnerabilities. Full details: https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html#security - Upgraded
pyasn1to v0.6.3 which fixes CVE-2026-30922, "Fixes Denial of Service in pyasn1 via Unbounded Recursion" - Upgraded Pygments to v2.20.0 which fixes CVE-2026-4539, "Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching"
- Upgraded
requeststo v2.34.2 which fixes CVE-2026-25645, "Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function" - Upgraded authlib to v1.7.2 which fixes:
- CVE-2026-44681, "Open Redirect in Authlib OIDC Implicit/Hybrid Authorization"
- CVE-2026-41479, "Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type"
- Upgraded
cryptographyto v49.0.0 which applies latest OpenSSL fixes
Full Changelog: https://github.com/saleor/saleor/compare/3.21.61...3.21.62
Security Fixes
- CVE-2026-30922 — pyasn1 denial of service via unbounded recursion
- CVE-2026-4539 — Pygments regular expression denial of service (ReDoS)
- CVE-2026-25645 — requests insecure temp file reuse in extract_zipped_paths()
- CVE-2026-44681 — authlib OIDC implicit/hybrid open redirect
- CVE-2026-41479 — authlib OAuth 2.0 open redirect via unsupported response_type
- Pillow v12.3.0 fixes multiple out‑of‑bounds reads/writes and denial‑of‑service issues
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]