TROYANOSYVIRUS
Back to CVEs

CVE-2025-68659

MEDIUM
4.3

Description

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have an application level denial of service vulnerabilityin the username change functionality at try.discourse.org. The vulnerability allows attackers to cause noticeable server delays and resource exhaustion by sending large JSON payloads to the username preference endpoint PUT /u//preferences/username, resulting in degraded performance for other users and endpoints. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published1/28/2026
Last Modified1/30/2026
Sourcenvd
Honeypot Sightings0

Affected Products

discourse:discourse

Weaknesses (CWE)

CWE-770

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.