Skip to content

Saleor

v3.23.17 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 19d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

cart checkout commerce composable e-commerce ecommerce
+12 more
graphql headless headless-commerce multichannel oms order-management payments pim python shop shopping-cart store

Affected surfaces

auth deps

Summary

AI summary

CVE fixes for private data exposure, heap buffer over-read, and header injection.

Full changelog

What's Changed

  • Upgraded django to v5.2.16 by @NyanKiyoshi in https://github.com/saleor/saleor/pull/19438

    Fixes:

    • CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response
    • CVE-2026-53877: Heap buffer over-read in GDALRaster
    • CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input

    More details: https://www.djangoproject.com/weblog/2026/jul/07/security-releases/

Full Changelog: https://github.com/saleor/saleor/compare/3.23.16...3.23.17

Security Fixes

  • CVE-2026-48588 — Potential exposure of private data via cached Set-Cookie response
  • CVE-2026-53877 — Heap buffer over-read in GDALRaster
  • CVE-2026-53878 — Header injection possibility due to DomainNameValidator accepting newlines

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Saleor

Get notified when new releases ship.

Sign up free

About Saleor

Django based open-sourced e-commerce storefront.

All releases →

Related context

Related tools

Beta — feedback welcome: [email protected]