Email Enumeration Vulnerability in Dify Open-Source LLM App Development Platform
CVE-2026-28288
5.5MEDIUM
What is CVE-2026-28288?
The Dify open-source LLM app development platform contains a vulnerability that allows attackers to differentiate responses from the Dify API for existing and non-existent accounts. This flaw enables potential attackers to perform email enumeration, accessing registered email addresses and compromising user privacy. The issue was addressed in version 1.9.0, which enhances the API's response handling to safeguard user information.
Affected Version(s)
dify < 1.9.0
