This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 19d
Productivity & Wikis
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
cart
checkout
commerce
composable
e-commerce
ecommerce
+12 more
graphql
headless
headless-commerce
multichannel
oms
order-management
payments
pim
python
shop
shopping-cart
store
Affected surfaces
auth
deps
Summary
AI summaryCVE fixes for private data exposure, heap buffer over-read, and header injection.
Full changelog
What's Changed
-
Upgraded django to v5.2.16 by @NyanKiyoshi in https://github.com/saleor/saleor/pull/19438
Fixes:
- CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response
- CVE-2026-53877: Heap buffer over-read in GDALRaster
- CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input
More details: https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
Full Changelog: https://github.com/saleor/saleor/compare/3.23.16...3.23.17
Security Fixes
- CVE-2026-48588 — Potential exposure of private data via cached Set-Cookie response
- CVE-2026-53877 — Heap buffer over-read in GDALRaster
- CVE-2026-53878 — Header injection possibility due to DomainNameValidator accepting newlines
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]