CVE-2026-53961

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holder to publish validly signed forged Bounce notifications that revoke a targeted user email. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*

History

14 Jul 2026, 20:37

Type Values Removed Values Added
CPE cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*
cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:*
References () https://github.com/discourse/discourse/commit/3a3d315a85ef3c6aabfc7e7bb38702059784f06b - () https://github.com/discourse/discourse/commit/3a3d315a85ef3c6aabfc7e7bb38702059784f06b - Patch
References () https://github.com/discourse/discourse/commit/61f12e13aa1b760f81d5ff60f12e3a7e77434b94 - () https://github.com/discourse/discourse/commit/61f12e13aa1b760f81d5ff60f12e3a7e77434b94 - Patch
References () https://github.com/discourse/discourse/commit/958f0cd831d65a49ec75f05343ca2c167679f0ea - () https://github.com/discourse/discourse/commit/958f0cd831d65a49ec75f05343ca2c167679f0ea - Patch
References () https://github.com/discourse/discourse/commit/aea35190791261bab258ebab05da279e78cdd0e6 - () https://github.com/discourse/discourse/commit/aea35190791261bab258ebab05da279e78cdd0e6 - Patch
References () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - Release Notes
References () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - Release Notes
References () https://github.com/discourse/discourse/security/advisories/GHSA-8f9m-v436-wr3x - () https://github.com/discourse/discourse/security/advisories/GHSA-8f9m-v436-wr3x - Vendor Advisory
First Time Discourse discourse
Discourse

09 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-09 22:17

Updated : 2026-07-14 20:37


NVD link : CVE-2026-53961

Mitre link : CVE-2026-53961

CVE.ORG link : CVE-2026-53961


JSON object : View

Products Affected

discourse

  • discourse
CWE
CWE-345

Insufficient Verification of Data Authenticity