CVE-2026-28288
MEDIUMDify <1.9.0 - Info Disclosure
Title source: llmDescription
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate email addresses registered with Dify. Version 1.9.0 fixes the issue.
Scores
CVSS v3
5.3
EPSS
0.0006
EPSS Percentile
17.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-204
Status
published
Affected Products (1)
dify/dify
< 1.9.0
Timeline
Published
Feb 27, 2026
Tracked Since
Feb 28, 2026