Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33756

28
FAUCET Score

OVERVIEW CVE-2026-33756 is a resource exhaustion vulnerability in Saleor e-commerce platform versions 2.0.0 through 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118. The vulnerability exists in Saleor's GraphQL query batching functionality, which accepts multiple GraphQL operations in a single HTTP request as a JSON array but lacks upper limits on the number of operations. This design flaw allows attackers to circumvent per-query complexity limits by submitting numerous operations in one request. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, meaning an unauthenticated attacker can easily trigger the vulnerability from the internet. The impact is limited to availability, as successful exploitation causes denial of service through resource exhaustion, with no confidentiality or integrity compromises. EXPLOITATION STATUS Currently, there is no evidence of active exploitation. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list and remains inactive on the Hot List, indicating minimal community attention and no publicly disclosed exploit code. The low EPSS score of 0.00105 suggests this vulnerability is not yet a primary target for threat actors, though organizations should prioritize patching given the high CVSS score and ease of exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 3.20.118CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.21.0, < 3.21.54CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.22.0, < 3.22.47CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 14th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / saleor/saleor/commit/7be352fa8c35875d6e66d36493ca7c14c101bd64
Patch
github.com / saleor/saleor/commit/cdb66da97abb7c86939e384914cd8d9194f378e8
Patch
github.com / saleor/saleor/commit/d6a94e95bd77f3f733fa66afd1b1ac72e863ca2a
Patch
github.com / saleor/saleor/commit/e42aa4d6e588982e78942b033af051c8ec8f43fa
Patch
github.com / saleor/saleor/commit/f0371bdd4cafcc841f1a9e7049cead6133bf7464
Patch
github.com / saleor/saleor/security/advisories/GHSA-24jw-f244-qfpp
PatchVendor Advisory