Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
References
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 15:22
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/discourse/discourse/commit/1f26c1163ce87a2abbd1d01780ab1b5fb16e75f6 - Patch | |
| References | () https://github.com/discourse/discourse/commit/8b773332b0f937dfcd894ed56d56fc5a81578d9d - Patch | |
| References | () https://github.com/discourse/discourse/commit/8d36da1b68c906592abde3f2e94d505cdf097435 - Patch | |
| References | () https://github.com/discourse/discourse/commit/d58988d46bb1019bfa8b8330ae81a1a134e08511 - Patch | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.1.5 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.4.2 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.5.1 - Release Notes | |
| References | () https://github.com/discourse/discourse/releases/tag/v2026.6.0 - Release Notes | |
| References | () https://github.com/discourse/discourse/security/advisories/GHSA-q456-4f8q-42vx - Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:* cpe:2.3:a:discourse:discourse:2026.6.0:*:*:*:latest:*:*:* |
|
| First Time |
Discourse discourse
Discourse |
09 Jul 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-09 22:17
Updated : 2026-07-13 15:22
NVD link : CVE-2026-59828
Mitre link : CVE-2026-59828
CVE.ORG link : CVE-2026-59828
JSON object : View
Products Affected
discourse
- discourse
CWE
