CVE-2026-31824 | Sylius up to 2.2.2 complete race condition (GHSA-7mp4-25j8-hp5q)
A vulnerability described as critical has been identified in Sylius up to 2.2.2. Affected by this vulnerability is an unknown functionality of the file /api/v2/shop/orders/{token}/complete. Executing a manipulation can lead to race condition.
This vulnerability is tracked as CVE-2026-31824. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.