magento2-40416: Customer address telephone validation accepting values like aaaa
Community fix magento2-40416 merged into magento/magento2 on 2026-02-10, released in 2.4.9; applies cleanly to 6 releases from 2.4.8 to 2.4.8-p5.
Fixes customer address telephone validation accepting values like aaaa edited
- Pull request title
- Customer address telephone validation does not work when there are no allowed characters
- Pull request
- magento/magento2#40416
- Issues
- #40361 human
- Author
- @yaroslav-kozar
- Merged
- 2026-02-10
- Fixed in
- 2.4.9
- Reported on
- 2.4.8-p3
- Categories
- Customer
- Components
- magento/module-customer
Labels
- Area
- Account
- Component
- Customer
- Priority
- P2
- Severity
- —
- Reported on (labels)
- 2.4.8-p3
Issue
Title and steps come from the upstream issue and pull request.
Description
aaaa as TelephoneSteps to reproduce
The customer address validation done in class
vendor/magento/module-customer/Model/Validator/Telephone.php does not work as intended if you type no allowed characters.Steps to reproduce:
- Create a customer account
- Go to address book and create an adress
- Enter
aaaa as TelephoneExpected result
Actual result
aaaa as TelephoneTaken from the upstream issue.
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 file-missing 2.4.6-p1 file-missing 2.4.6-p2 file-missing 2.4.6-p3 file-missing 2.4.6-p4 file-missing 2.4.6-p5 file-missing 2.4.6-p6 file-missing 2.4.6-p7 file-missing 2.4.6-p8 file-missing 2.4.6-p9 file-missing 2.4.6-p10 file-missing 2.4.6-p11 file-missing 2.4.6-p12 file-missing 2.4.6-p13 file-missing 2.4.6-p14 file-missing 2.4.6-p15 file-missing | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 file-missing 2.4.7-p1 file-missing 2.4.7-p2 file-missing 2.4.7-p3 file-missing 2.4.7-p4 file-missing 2.4.7-p5 file-missing 2.4.7-p6 file-missing 2.4.7-p7 file-missing 2.4.7-p8 file-missing 2.4.7-p9 file-missing 2.4.7-p10 file-missing | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseunit: could not run before, could not run after |
| 2.4.9 | 2.4.9 conflictcontains the fix | 2.4.9: no test data |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 98.0%. Probability it is security relevant: 5.4%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 93.9%, refactor 2.9%, tests_only 1.4%, feature 0.7%, docs_only 0.6%, dependency 0.5% | 86.0% |
| Area | customer | customer 97.1%, admin 0.8%, checkout 0.5% | 93.6% |
| Reported version | 2.4.8-p3 | 2.4.8-p3 63.2%, 2.4.8-p4 2.7%, 2.4.8-p2 1.9% | 39.5% |
| Scope | 1.04 of 2 | 1 67.3%, 2 18.6%, 0 14.2% | 26.0% |
| Risk | 0.26 of 2 | 0 80.0%, 1 14.2%, 2 5.8% | 49.5% |
| Worth backporting | 1.63 of 2 | 2 71.7%, 1 19.6%, 0 8.7% | 34.0% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40416/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-40416 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40416 Issue: https://github.com/magento/magento2/issues/40361 Author: @yaroslav-kozar Source commit: 5e1c38cdaab6d4b88829fc5634d4579e8480a912 Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
