OVERVIEW CVE-2026-33756 is a resource exhaustion vulnerability in Saleor e-commerce platform versions 2.0.0 through 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118. The vulnerability exists in Saleor's GraphQL query batching functionality, which accepts multiple GraphQL operations in a single HTTP request as a JSON array but lacks upper limits on the number of operations. This design flaw allows attackers to circumvent per-query complexity limits by submitting numerous operations in one request. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning an unauthenticated attacker can easily trigger the vulnerability from the internet. The impact is limited to availability, as successful exploitation causes denial of service through resource exhaustion, with no confidentiality or integrity compromises. EXPLOITATION STATUS Currently, there is no evidence of active exploitation. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on the Hot List, indicating minimal community attention and no publicly disclosed exploit code. The low EPSS score of 0.00105 suggests this vulnerability is not yet a primary target for threat actors, though organizations should prioritize patching given the high CVSS score and ease of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 3.20.118CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.21.0, < 3.21.54CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.22.0, < 3.22.47CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.