Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the group email settings test endpoint could be used to make the server initiate outbound connections to arbitrary hosts and ports. This could allow probing of internal network infrastructure. The endpoint was accessible to non-staff group owners. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.
References
Configurations
Configuration 1 (hide)
|
History
09 Apr 2026, 15:51
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.0 |
| First Time |
Discourse
Discourse discourse |
|
| CPE | cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest.1:*:*:* cpe:2.3:a:discourse:discourse:*:*:*:*:latest:*:*:* cpe:2.3:a:discourse:discourse:2026.3.0:*:*:*:latest:*:*:* |
|
| References | () https://github.com/discourse/discourse/commit/e75cf456e8e318290c569bd6e8fa0f2586ffc530 - Patch | |
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-5976-77mj-m4h3 - Vendor Advisory |
31 Mar 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 18:16
Updated : 2026-04-09 15:51
NVD link : CVE-2026-33185
Mitre link : CVE-2026-33185
CVE.ORG link : CVE-2026-33185
JSON object : View
Products Affected
discourse
- discourse
CWE
CWE-918
Server-Side Request Forgery (SSRF)
