UPSTREAM FIX

magento2-33139: Rest API rejecting capital letters in product attribute codes

Community fix magento2-33139 merged into magento/magento2 on 2026-01-31, released in 2.4.9; applies cleanly to 33 releases from 2.4.6 to 2.4.8-p5.

Fixes the Rest API rejecting capital letters in product attribute codes edited

Pull request title
Rest API and Magento backend use different validation methods for attribute_code when creating new attributes
Pull request
magento/magento2#33139
Issues
#33138 human
Author
@homecoded
Merged
2026-01-31
Fixed in
2.4.9
Reported on
2.4.2
Categories
Web API
Components
magento/module-catalog

Labels

Area
APIs
Component
Api
Priority
P2
Severity
—
Reported on (labels)
2.4.2

Issue

Title and steps come from the upstream issue and pull request.

Description

1. I can create product attributes with uppercase letters in attribute_code through backend.
2. I cannot create product attributes with uppercase letters in attribute_code through Rest API.
3. Backend and rest api do not work similarly in creating product attributes in regards to attribute_code.-

Steps to reproduce

1. Go to backend
2. Open Stores -> Attribute -> Product
3. Click "Add New Attribute"
4. Enter arbitrary value in "Default Label"
5. Under "Advanced Attribute Properties" enter an "Attribute Code" that contains an upper case letter, e.g. "Test_Attribute"
6. Hit save (works!)
7. Setup Rest-API and send a request to create a product attribute with an attribute code that has uppercase letters, e.g. "Test_Attribute2" (see sample script below)
8. Check response: "message":"Invalid value of ""%value"" provided for the %fieldName field.","parameters":{"fieldName":"attribute_code","value":"Test_Attribute2"}

Sample bash script for verification (replace baseurl and username/password)
BASE_URL='http://localhost/'
TOKEN=$(curl -X POST "${BASE_URL}index.php/rest/V1/integration/admin/token" \
-H "Content-Type:application/json" \
-d '{"username":"admin", "password":"password123"}')
TOKEN=$(echo $TOKEN | sed "s/\"//g");

curl -X POST "${BASE_URL}index.php/rest/V1/products/attributes" \
-H "authorization: Bearer ${TOKEN}" \
-H 'content-type: application/json' \
-d '{
 "attribute": {
   "attribute_code": "branding_Tester4",
   "default_frontend_label": "Testing",
   "frontend_input": "text"
 }
}'

Expected result

1. I expect that I can create the same kind of product attributes through backend and Rest-API
2. I expect that I can use uppercase letters in attribute codes when creating product attributes through backend and frontend.
3. I expect that backend and rest api work similarly in creating product attributes.

Actual result

1. I can create product attributes with uppercase letters in attribute_code through backend.
2. I cannot create product attributes with uppercase letters in attribute_code through Rest API.
3. Backend and rest api do not work similarly in creating product attributes in regards to attribute_code.-

---
Please provide [Severity](https://devdocs.magento.com/guides/v2.4/contributor-guide/contributing.html#backlog) assessment for the Issue as Reporter. This information will help during Confirmation and Issue triage processes.

- [ ] Severity: S0 _- Affects critical data or functionality and leaves users without workaround._
- [ ] Severity: S1 _- Affects critical data or functionality and forces users to employ a workaround._
- [x] Severity: S2 _- Affects non-critical data or functionality and forces users to employ a workaround._
- [ ] Severity: S3 _- Affects non-critical data or functionality and does not force users to employ a workaround._
- [ ] Severity: S4 _- Affects aesthetics, professional look and feel, “quality” or “usability”._

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: passes before and after (test does not cover the fix)unit: passes before and after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: passes before and after (test does not cover the fix)unit: passes before and after
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 95.6%. Probability it is security relevant: 1.1%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 92.8%, refactor 4.7%, feature 1.0%, tests_only 0.9%, dependency 0.4%, docs_only 0.3%83.6%
Areacatalogcatalog 61.3%, graphql_api 30.9%, admin 4.2%39.8%
Reported version2.4.22.4.2 63.2%, 2.4.2-p2 4.8%, 2.4.2-p1 4.3%39.7%
Scope0.83 of 21 52.0%, 0 32.6%, 2 15.5%10.0%
Risk0.40 of 20 65.6%, 1 29.2%, 2 5.2%27.8%
Worth backporting1.56 of 22 65.1%, 1 25.8%, 0 9.1%24.8%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-33139/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-catalog
Bundle README (what the ZIP ships)
# magento2-33139

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/33139
Issue: https://github.com/magento/magento2/issues/33138
Author: @homecoded
Source commit: 2ace85359508380fa4e24cac04ea7503f35ec738
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.