UPSTREAM FIX

magento2-40416: Customer address telephone validation accepting values like aaaa

Community fix magento2-40416 merged into magento/magento2 on 2026-02-10, released in 2.4.9; applies cleanly to 6 releases from 2.4.8 to 2.4.8-p5.

Fixes customer address telephone validation accepting values like aaaa edited

Pull request title
Customer address telephone validation does not work when there are no allowed characters
Pull request
magento/magento2#40416
Issues
#40361 human
Author
@yaroslav-kozar
Merged
2026-02-10
Fixed in
2.4.9
Reported on
2.4.8-p3
Categories
Customer
Components
magento/module-customer

Labels

Area
Account
Component
Customer
Priority
P2
Severity
—
Reported on (labels)
2.4.8-p3

Issue

Title and steps come from the upstream issue and pull request.

Description

Address is saved with aaaa as Telephone

Steps to reproduce

Hello,

The customer address validation done in class vendor/magento/module-customer/Model/Validator/Telephone.php does not work as intended if you type no allowed characters.

Steps to reproduce:
- Create a customer account
- Go to address book and create an adress
- Enter aaaa as Telephone

Expected result

I should have an error message saying the telephone is invalid

Actual result

Address is saved with aaaa as Telephone

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 file-missing 2.4.6-p1 file-missing 2.4.6-p2 file-missing 2.4.6-p3 file-missing 2.4.6-p4 file-missing 2.4.6-p5 file-missing 2.4.6-p6 file-missing 2.4.6-p7 file-missing 2.4.6-p8 file-missing 2.4.6-p9 file-missing 2.4.6-p10 file-missing 2.4.6-p11 file-missing 2.4.6-p12 file-missing 2.4.6-p13 file-missing 2.4.6-p14 file-missing 2.4.6-p15 file-missing
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 file-missing 2.4.7-p1 file-missing 2.4.7-p2 file-missing 2.4.7-p3 file-missing 2.4.7-p4 file-missing 2.4.7-p5 file-missing 2.4.7-p6 file-missing 2.4.7-p7 file-missing 2.4.7-p8 file-missing 2.4.7-p9 file-missing 2.4.7-p10 file-missing
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseunit: could not run before, could not run after
2.4.9
2.4.9 conflictcontains the fix
2.4.9: no test data

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 98.0%. Probability it is security relevant: 5.4%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 93.9%, refactor 2.9%, tests_only 1.4%, feature 0.7%, docs_only 0.6%, dependency 0.5%86.0%
Areacustomercustomer 97.1%, admin 0.8%, checkout 0.5%93.6%
Reported version2.4.8-p32.4.8-p3 63.2%, 2.4.8-p4 2.7%, 2.4.8-p2 1.9%39.5%
Scope1.04 of 21 67.3%, 2 18.6%, 0 14.2%26.0%
Risk0.26 of 20 80.0%, 1 14.2%, 2 5.8%49.5%
Worth backporting1.63 of 22 71.7%, 1 19.6%, 0 8.7%34.0%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40416/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (1): magento/module-customer
Bundle README (what the ZIP ships)
# magento2-40416

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40416
Issue: https://github.com/magento/magento2/issues/40361
Author: @yaroslav-kozar
Source commit: 5e1c38cdaab6d4b88829fc5634d4579e8480a912
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.