magento2-40742: GraphQL pageSize above the configured maximum being accepted without error
Community fix magento2-40742 merged into magento/magento2 on 2026-05-20, not in a release yet; applies cleanly to 18 releases from 2.4.7 to 2.4.9.
Fixes GraphQL pageSize above the configured maximum being accepted without error edited
- Pull request title
- [Bug] GraphQL SearchCriteriaValidator not loaded — removed by module-graph-ql di.xml array override
- Pull request
- magento/magento2#40742
- Issues
- #40762 pr-derived
- Author
- @mtytula
- Merged
- 2026-05-20
- Fixed in
- no release yet
- Reported on
- —
- Categories
- GraphQL
- Components
- magento/module-graph-ql
Labels
- Area
- Catalog
- Component
- GraphQL
- Priority
- P3
- Severity
- —
- Reported on (labels)
- 2.4.x
Issue
Title and steps come from the upstream issue and pull request.
The upstream issue and pull request have no structured description.
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 conflict 2.4.6-p1 conflict 2.4.6-p2 conflict 2.4.6-p3 conflict 2.4.6-p4 conflict 2.4.6-p5 conflict 2.4.6-p6 conflict 2.4.6-p7 conflict 2.4.6-p8 conflict 2.4.6-p9 conflict 2.4.6-p10 conflict 2.4.6-p11 conflict 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 clean 2.4.7-p8 clean 2.4.7-p9 clean 2.4.7-p10 clean | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: fails before (after: error)integration: could not run before, could not run after · api-functional: fails before, passes after |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 clean 2.4.8-p3 clean 2.4.8-p4 clean 2.4.8-p5 clean | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: fails before, passes afterintegration: fails before, passes after · api-functional: fails before, passes after |
| 2.4.9 | 2.4.9 clean | 2.4.9: fails before, passes afterintegration: fails before, passes after · api-functional: fails before, passes after |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 98.3%. Probability it is security relevant: 9.8%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 92.9%, refactor 2.8%, tests_only 1.4%, feature 1.4%, dependency 0.9%, docs_only 0.6% | 83.6% |
| Area | graphql_api | graphql_api 90.9%, framework 6.3%, catalog 1.1% | 80.7% |
| Reported version | 2.4.7-p9 | 2.4.7-p9 53.5%, 2.4.7 14.7%, 2.4.7-p8 1.9% | 30.1% |
| Scope | 0.88 of 2 | 1 47.2%, 0 32.4%, 2 20.4% | 5.4% |
| Risk | 0.40 of 2 | 0 65.1%, 1 29.3%, 2 5.6% | 26.9% |
| Worth backporting | 1.72 of 2 | 2 77.4%, 1 16.8%, 0 5.8% | 44.5% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-40742/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-40742 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/40742 Issue: https://github.com/magento/magento2/issues/40762 Author: @mtytula Source commit: c51178cef5a5f282590fe2e5a4b995835d9cacee Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
