Email Enumeration Vulnerability in Dify Open-Source LLM App Development Platform
CVE-2026-28288
5.5MEDIUM
What is CVE-2026-28288?
The Dify open-source LLM app development platform contains a vulnerability that allows attackers to differentiate responses from the Dify API for existing and non-existent accounts. This flaw enables potential attackers to perform email enumeration, accessing registered email addresses and compromising user privacy. The issue was addressed in version 1.9.0, which enhances the API's response handling to safeguard user information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dify < 1.9.0
