{"data":{"id":"magento2-40433","source":"github-pr","sourceRef":"magento/magento2#40433","title":"Incorrect handling of the GET params","pr":{"number":40433,"url":"https://github.com/magento/magento2/pull/40433","author":"sydor-dev","mergedAt":"2026-05-12T11:41:36Z","mergeCommit":"3b3f02060a6650389b854dc0f7f87e4900ab51a6","headCommit":"b0df10e5b1956b17a112e4eca3e3affbe0d2e154","baseRef":"2.4-develop","diffSha256":"15d9c22b89f1029034d62459fdda3cfa66b2161010119d32c4b9c2b4033e7f72"},"issues":[{"number":40405,"url":"https://github.com/magento/magento2/issues/40405","title":"Incorrect handling of the GET params","labels":["Area: Catalog","Component: Catalog","Issue: Confirmed","Priority: P2","Progress: PR Created","Progress: done","Reported on 2.4.8-p1","Reproduced on 2.4.x"],"kind":"human"}],"fixedIn":null,"containingTags":[],"reportedOn":"2.4.8-p1","codeMatch":{"2.4.6":"clean","2.4.6-p1":"clean","2.4.6-p2":"clean","2.4.6-p3":"clean","2.4.6-p4":"clean","2.4.6-p5":"clean","2.4.6-p6":"clean","2.4.6-p7":"clean","2.4.6-p8":"clean","2.4.6-p9":"clean","2.4.6-p10":"clean","2.4.6-p11":"clean","2.4.6-p12":"clean","2.4.6-p13":"clean","2.4.6-p14":"clean","2.4.6-p15":"clean","2.4.7":"clean","2.4.7-p1":"clean","2.4.7-p2":"clean","2.4.7-p3":"clean","2.4.7-p4":"clean","2.4.7-p5":"clean","2.4.7-p6":"clean","2.4.7-p7":"clean","2.4.7-p8":"clean","2.4.7-p9":"clean","2.4.7-p10":"clean","2.4.8":"clean","2.4.8-p1":"clean","2.4.8-p2":"clean","2.4.8-p3":"clean","2.4.8-p4":"clean","2.4.8-p5":"clean","2.4.9":"clean"},"affectedVersions":["2.4.6","2.4.6-p1","2.4.6-p2","2.4.6-p3","2.4.6-p4","2.4.6-p5","2.4.6-p6","2.4.6-p7","2.4.6-p8","2.4.6-p9","2.4.6-p10","2.4.6-p11","2.4.6-p12","2.4.6-p13","2.4.6-p14","2.4.6-p15","2.4.7","2.4.7-p1","2.4.7-p2","2.4.7-p3","2.4.7-p4","2.4.7-p5","2.4.7-p6","2.4.7-p7","2.4.7-p8","2.4.7-p9","2.4.7-p10","2.4.8","2.4.8-p1","2.4.8-p2","2.4.8-p3","2.4.8-p4","2.4.8-p5","2.4.9"],"components":["magento/module-catalog","magento/module-wishlist"],"files":[{"path":"app/code/Magento/Catalog/Block/Product/View.php","change":"modified","package":"magento/module-catalog"},{"path":"app/code/Magento/Wishlist/Plugin/Helper/Product/View.php","change":"modified","package":"magento/module-wishlist"}],"stripped":{"tests":["app/code/Magento/Catalog/Test/Unit/Block/Product/AbstractProductTest.php","app/code/Magento/Catalog/Test/Unit/Block/Product/ViewTest.php"],"docs":[],"outsideCode":[]},"linesChanged":29,"mergeBatched":false,"excluded":null,"sections":{"description":"M2 Returns 500 code which is one of the reasons of DDoS attack to the merchant","stepsToReproduce":"Open any product and set the incorrect qty params on simple product","expectedResult":"M2 Returns 200(OK) code which can help prevent DDoS attack to the merchant","actualResult":"M2 Returns 500 code which is one of the reasons of DDoS attack to the merchant","source":"issue"},"signatures":[],"labels":{"area":["Catalog"],"component":["Catalog"],"priority":"P2","severity":null,"reportedOn":["2.4.8-p1"]},"categories":["Catalog/Product"],"triage":{"model":"@cf/cloudflare/clef","requestHash":"5f1fcbd03d7c45d0223faeb47ec7d47f922e3b3f1f232e3e495452a2fcf4689f","isBugfix":0.9811,"changeKind":{"choice":"bugfix","probabilities":{"bugfix":0.9494,"feature":0.0088,"refactor":0.019,"tests_only":0.0108,"docs_only":0.0055,"dependency":0.0065},"confidence":0.8825},"scope":{"score":0.8769,"probabilities":{"0":0.2781,"1":0.5669,"2":0.155},"confidence":0.1341},"risk":{"score":0.2237,"probabilities":{"0":0.8098,"1":0.1566,"2":0.0336},"confidence":0.5223},"area":{"choice":"catalog","probabilities":{"catalog":0.8158,"checkout":0.0412,"customer":0.0103,"admin":0.0131,"graphql_api":0.0087,"framework":0.0235,"frontend":0.0733,"other":0.0141},"confidence":0.6272},"securityRelevant":0.0613,"reportedVersion":{"choice":"2.4.8-p1","probabilities":{"2.4.0":0.0014,"2.4.0-p1":0.0016,"2.4.1":0.0014,"2.4.1-p1":0.0016,"2.4.2":0.0014,"2.4.2-p1":0.0018,"2.4.2-p2":0.0018,"2.4.3":0.0015,"2.4.3-p1":0.0019,"2.4.3-p2":0.0019,"2.4.3-p3":0.0017,"2.4.4":0.0015,"2.4.4-p1":0.0017,"2.4.4-p10":0.002,"2.4.4-p11":0.0023,"2.4.4-p12":0.0025,"2.4.4-p13":0.0019,"2.4.4-p14":0.0021,"2.4.4-p15":0.0025,"2.4.4-p16":0.002,"2.4.4-p17":0.002,"2.4.4-p18":0.0022,"2.4.4-p2":0.0015,"2.4.4-p3":0.0015,"2.4.4-p4":0.0015,"2.4.4-p5":0.0017,"2.4.4-p6":0.0016,"2.4.4-p7":0.0018,"2.4.4-p8":0.0024,"2.4.4-p9":0.0017,"2.4.5":0.0018,"2.4.5-p1":0.0017,"2.4.5-p10":0.0017,"2.4.5-p11":0.0021,"2.4.5-p12":0.0022,"2.4.5-p13":0.002,"2.4.5-p14":0.0025,"2.4.5-p15":0.002,"2.4.5-p16":0.002,"2.4.5-p17":0.002,"2.4.5-p2":0.0015,"2.4.5-p3":0.0016,"2.4.5-p4":0.0017,"2.4.5-p5":0.0018,"2.4.5-p6":0.0019,"2.4.5-p7":0.002,"2.4.5-p8":0.0023,"2.4.5-p9":0.0017,"2.4.6":0.0043,"2.4.6-p1":0.0027,"2.4.6-p10":0.0054,"2.4.6-p11":0.0042,"2.4.6-p12":0.3154,"2.4.6-p13":0.003,"2.4.6-p14":0.0026,"2.4.6-p15":0.0022,"2.4.6-p2":0.0015,"2.4.6-p3":0.0018,"2.4.6-p4":0.0018,"2.4.6-p5":0.002,"2.4.6-p6":0.0021,"2.4.6-p7":0.0023,"2.4.6-p8":0.0029,"2.4.6-p9":0.0025,"2.4.7":0.0023,"2.4.7-p1":0.0021,"2.4.7-p10":0.0023,"2.4.7-p2":0.0019,"2.4.7-p3":0.0022,"2.4.7-p4":0.0031,"2.4.7-p5":0.0033,"2.4.7-p6":0.003,"2.4.7-p7":0.0031,"2.4.7-p8":0.0034,"2.4.7-p9":0.0018,"2.4.8":0.03,"2.4.8-p1":0.4343,"2.4.8-p2":0.0342,"2.4.8-p3":0.0076,"2.4.8-p4":0.0066,"2.4.8-p5":0.0063,"2.4.9":0.0021,"unspecified":0.0048},"confidence":0.282},"backportWorthy":{"score":1.7639,"probabilities":{"0":0.0396,"1":0.1569,"2":0.8035},"confidence":0.5078}},"curated":{"title":"Fixes the product page TypeError when the qty request parameter is not numeric","description":"A non-numeric qty request parameter, such as qty=string, can reach the add-to-cart template and cause TypeError: Unsupported operand types: string * int, an HTTP 500 response on product view pages. The Wishlist product view plugin now ignores non-numeric qty, and getProductDefaultQty() ignores non-numeric preconfigured qty values and uses a positive minimum sale qty, else 1.","categories":["Catalog/Product"],"author":"claude-code/opus-5.5","date":"2026-10-06","reviewedBy":null},"tests":{"2.4.8-p5":{"before":"not-runnable","after":"error","adapted":false,"runAt":"2026-10-06T09:20:19.005Z","releaseCommit":"870a22c63d9d9b68fa3297962e2d5d5841115814","suites":{"unit":{"before":"not-runnable","after":"error","runAt":"2026-10-06T09:20:19.005Z"}}},"2.4.9":{"before":"fail","after":"pass","adapted":false,"runAt":"2026-10-06T09:20:18.770Z","releaseCommit":"755e34dd689021c5165db9d35ecff74f7dc51527","suites":{"unit":{"before":"fail","after":"pass","runAt":"2026-10-06T09:20:18.770Z"}}},"2.4.7-p10":{"before":"not-runnable","after":"error","adapted":false,"runAt":"2026-10-06T09:29:28.285Z","releaseCommit":"72561bf80652f57cc642a03e2c9a51d74a285b14","suites":{"unit":{"before":"not-runnable","after":"error","runAt":"2026-10-06T09:29:28.285Z"}}}}},"_documentation":"https://magento.watch/api","_description":"Upstream fix magento2-40433 details"}