CVE-2025-68662

Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2025.12.0:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2026.1.0:*:*:*:stable:*:*:*

History

30 Jan 2026, 20:44

Type Values Removed Values Added
References () https://github.com/discourse/discourse/security/advisories/GHSA-gcfp-rjfc-925c - () https://github.com/discourse/discourse/security/advisories/GHSA-gcfp-rjfc-925c - Third Party Advisory
First Time Discourse
Discourse discourse
CPE cpe:2.3:a:discourse:discourse:2026.1.0:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:stable:*:*:*
cpe:2.3:a:discourse:discourse:2025.12.0:*:*:*:stable:*:*:*

28 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-28 20:16

Updated : 2026-01-30 20:44


NVD link : CVE-2025-68662

Mitre link : CVE-2025-68662

CVE.ORG link : CVE-2025-68662


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-918

Server-Side Request Forgery (SSRF)