vulns.co
/
GKData.io MCP

Sylius · 1 min read

Sylius: promotion entitlement must be checked and consumed atomically

Promotion eligibility used stale in-memory counts, while consumption was persisted later without synchronization. Absolute counter writes could also lose concurrent updates. The failed boundary was between a provisional eligibility decision and committed entitlement across global promotion, coupon and per-customer limits.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial lesson: model the limit check and entitlement consumption as one serialized decision. Accounting correctness alone does not prove eligibility correctness. In owned local models, verify that committed usage never exceeds the authorized allowance, including cancellation semantics.

Before reading

  • Basic authorization, application state machines and database transaction concepts

Context and limits

  • The maintainer reports limit overruns without required authentication; a limited promotion or coupon and overlapping order processing are prerequisites. Financial loss is a potential consequence, not a measured production incident.
  • The advisory lists fixes in 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12 and 2.2.3. Consult its branch-specific affected ranges. Patch dates are not asserted; resource edition remains null.
  • NoResponseMate published the advisory. Reporters are Djibril Mounkoro (whiteov3rflow) and Bartłomiej Nowiński (bnBart); CVE-2026-31824.

Sources and provenance

  1. Promotion Usage Limit Bypass via Race Condition Sylius · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software