Skip to content

Mitigate cart number enumeration attacks#4231

Open
lukeholder wants to merge 3 commits into5.6from
feature/cart-rate-limit
Open

Mitigate cart number enumeration attacks#4231
lukeholder wants to merge 3 commits into5.6from
feature/cart-rate-limit

Conversation

@lukeholder
Copy link
Member

Description

  • Added rate limiting to all cart controller requests that explicitly pass an order/cart number.
  • Moved to a more secure cart number generator function.

@lukeholder lukeholder requested a review from a team as a code owner February 13, 2026 02:16
@lukeholder lukeholder changed the base branch from 5.x to 5.6 February 13, 2026 02:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant