Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This vulnerability is fixed in 3.6.2 and 3.6.0.beta2.
CVSS
No CVSS.
References
Configurations
No configuration.
History
28 Oct 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-28 21:15
Updated : 2025-10-30 15:05
NVD link : CVE-2025-61598
Mitre link : CVE-2025-61598
CVE.ORG link : CVE-2025-61598
JSON object : View
Products Affected
No product.
CWE
CWE-524
Use of Cache Containing Sensitive Information
