What is CVE-2026-35401?
Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can include many GraphQL mutations or queries in a single API call using aliases or chaining multiple mutations, resulting in resource exhaustion. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
Timeline
- 2026-04-08Published to the U.S. National Vulnerability Database (NVD)
- 2026-07-24NVD record last updated
Affected product
Saleor
Remediation Steps
- Isolate affected Firepower/ASA devices from production network immediately
- Perform forensic analysis for command and control communication artifacts
- Apply latest Cisco ASA/FTD firmware patches from Cisco security advisories
- Implement network segmentation and enhanced monitoring for lateral movement
- Reset all administrative credentials and implement MFA on management interfaces
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of April 2026 (April 27 – May 3)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.