Dify User Enumeration via Observable Response Discrepancy
CVE-2026-28288
Verified
Description
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.
Severity
Medium
CVSS Score
5.3
Exploit Probability
1%
Published Date
March 26, 2026
Template Author
dhiyaneshdk
CVE-2026-28288.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-28288
CWE ID:
cwe-204
Remediation Steps
Update to version 1.9.0 or later.