/Vulnerability Library

Dify User Enumeration via Observable Response Discrepancy

CVE-2026-28288
Verified

Description

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Published Date

March 26, 2026

Template Author

dhiyaneshdk

CVE-2026-28288.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-28288
CWE ID:
cwe-204

References

https://github.com/langgenius/dify/security/advisories/GHSA-9qpf-wcv3-w3qxhttps://github.com/langgenius/dify/issues/24323

Remediation Steps

Update to version 1.9.0 or later.