Data Exposure Vulnerability in Discourse by Discourse Inc.
CVE-2026-33422
What is CVE-2026-33422?
Discourse, a popular open-source discussion platform, has a vulnerability that exposes the IP addresses of flagged users to all users with access to the review queue. This flaw exists in versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, allowing unauthorized visibility of sensitive data. The affected versions do not provide any known workarounds, making it crucial for users to update to the patched versions to safeguard user privacy.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
discourse >= 2026.1.0-latest, < 2026.1.2 < 2026.1.0-latest, 2026.1.2
discourse >= 2026.2.0-latest, < 2026.2.1 < 2026.2.0-latest, 2026.2.1
discourse = 2026.3.0-latest = 2026.3.0-latest