UPSTREAM FIX

magento2-40433: Product page TypeError when the qty request parameter is not numeric

Community fix magento2-40433 merged into magento/magento2 on 2026-05-12, not in a release yet; applies cleanly to 34 releases from 2.4.6 to 2.4.9.

Fixes the product page TypeError when the qty request parameter is not numeric edited

Pull request title
Incorrect handling of the GET params
Pull request
magento/magento2#40433
Issues
#40405 human
Author
@sydor-dev
Merged
2026-05-12
Fixed in
no release yet
Reported on
2.4.8-p1
Categories
Catalog/Product
Components
magento/module-catalog, magento/module-wishlist

Labels

Area
Catalog
Component
Catalog
Priority
P2
Severity
—
Reported on (labels)
2.4.8-p1

Issue

Title and steps come from the upstream issue and pull request.

Description

M2 Returns 500 code which is one of the reasons of DDoS attack to the merchant

Steps to reproduce

Open any product and set the incorrect qty params on simple product

Expected result

M2 Returns 200(OK) code which can help prevent DDoS attack to the merchant

Actual result

M2 Returns 500 code which is one of the reasons of DDoS attack to the merchant

Taken from the upstream issue.

Code match per tag

Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.

LineCode match per tagTests
2.4.6
2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 clean 2.4.6-p13 clean 2.4.6-p14 clean 2.4.6-p15 clean
2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data
2.4.7
2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean
2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: test files do not apply to this releaseunit: could not run before, could not run after
2.4.8
2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean
2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: test files do not apply to this releaseunit: could not run before, could not run after
2.4.9
2.4.9 clean
2.4.9: fails before, passes afterunit: fails before, passes after

Triage

Model @cf/cloudflare/clef. Probability this is a bug fix: 98.1%. Probability it is security relevant: 6.1%.

Show the model's answers and probabilities
QuestionAnswerProbabilitiesConfidence
Change kindbugfixbugfix 94.9%, refactor 1.9%, tests_only 1.1%, feature 0.9%, dependency 0.7%, docs_only 0.5%88.3%
Areacatalogcatalog 81.6%, frontend 7.3%, checkout 4.1%62.7%
Reported version2.4.8-p12.4.8-p1 43.4%, 2.4.6-p12 31.5%, 2.4.8-p2 3.4%28.2%
Scope0.88 of 21 56.7%, 0 27.8%, 2 15.5%13.4%
Risk0.22 of 20 81.0%, 1 15.7%, 2 3.4%52.2%
Worth backporting1.76 of 22 80.3%, 1 15.7%, 0 4.0%50.8%

Download

For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40433/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.

Packages (2): magento/module-catalog, magento/module-wishlist
Bundle README (what the ZIP ships)
# magento2-40433

Community fix merged upstream into magento/magento2, adapted by magento.watch.
This is not a patch published by Adobe.

Pull request: https://github.com/magento/magento2/pull/40433
Issue: https://github.com/magento/magento2/issues/40405
Author: @sydor-dev
Source commit: b0df10e5b1956b17a112e4eca3e3affbe0d2e154
Modifications: test files and documentation removed, paths rewritten relative to each Composer package.
Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code.
Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)

Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.

Sources

Łukasz Bajsarowicz
Built by

Łukasz Bajsarowicz, e-commerce architect

Magento and Adobe Commerce architecture, upgrades, performance and audits for merchants and agencies since 2015; magento.watch is the tooling I use on those projects.

Open source, maintained on weekends.