Hostname Validation Issue in Discourse Discussion Platform
CVE-2025-68662
7.6HIGH
What is CVE-2025-68662?
A hostname validation issue has been identified in the Discourse discussion platform, affecting versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. This vulnerability allows an attacker to potentially bypass Server-Side Request Forgery (SSRF) protections under specific conditions. Users and administrators are urged to upgrade to the patched versions as no workarounds are available to mitigate this issue.
Affected Version(s)
discourse < 3.5.4 < 3.5.4
discourse >= 2025.11.0-latest, < 2025.11.2 < 2025.11.0-latest, 2025.11.2
discourse >= 2025.12.0-latest, < 2025.12.1 < 2025.12.0-latest, 2025.12.1