4.3

CVSS3.1

CVE-2026-33393 - Discourse fixes loose hostname matching in spam host allowlist

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allowed_spam_host_domains` check used `String#end_with?` without domain boundary validation, allowing domains like `attacker-example.com` to bypass spam protection when `example.com` w…

πŸ“… Published: March 19, 2026, 10:04 p.m. πŸ”„ Last Modified: March 20, 2026, 8:15 p.m.

6.5

CVSS3.1

CVE-2026-33355 - Discourse filters whisper posts from private-posts feed

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/private-posts` endpoint did not apply post-type visibility filtering, allowing regular PM participants to see whisper posts in PM topics they had access to. Versions 2026.3.0-latest.1…

πŸ“… Published: March 19, 2026, 10:01 p.m. πŸ”„ Last Modified: March 20, 2026, 6:10 p.m.

2.4

CVSS4.0

CVE-2026-30873 - OpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokens

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis by breaking input expressions into tokens, contains a memory leak vulnerability when extracting string literals, field la…

πŸ“… Published: March 19, 2026, 10:01 p.m. πŸ”„ Last Modified: March 21, 2026, 3:26 a.m.

5.4

CVSS3.1

CVE-2026-33410 - Discourse hardens chat DM channel creation and expansion

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two authorization issues in the chat direct message API. First, when creating a direct message channel or adding users to an existing one, the `target_groups` parameter was passed direc…

πŸ“… Published: March 19, 2026, 9:57 p.m. πŸ”„ Last Modified: March 20, 2026, 4:11 p.m.

9.5

CVSS4.0

CVE-2026-30872 - OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookup

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) rece…

πŸ“… Published: March 19, 2026, 9:56 p.m. πŸ”„ Last Modified: March 20, 2026, 7:41 p.m.

4.3

CVSS3.1

CVE-2026-32099 - Discourse prevents hidden profile data leak via user onebox

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a user has `hide_profile` enabled, their bio, location, and website were still exposed through the user onebox preview. An authenticated user could request a onebox for a hidden user's…

πŸ“… Published: March 19, 2026, 9:52 p.m. πŸ”„ Last Modified: March 20, 2026, 6:38 p.m.

8.8

CVSS3.1

CVE-2026-4342 - ingress-nginx comment-based nginx configuration injection

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in…

πŸ“… Published: March 19, 2026, 9:50 p.m. πŸ”„ Last Modified: March 21, 2026, 4:01 a.m.

9.5

CVSS4.0

CVE-2026-30871 - OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.ar…

πŸ“… Published: March 19, 2026, 9:49 p.m. πŸ”„ Last Modified: March 20, 2026, 8:16 p.m.

8.2

CVSS4.0

CVE-2026-29072 - Discourse missing permission check for policy creation in discourse-policy

Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right conditions. Versions 2026.3.0-latest.1, 2026.2.1, and …

πŸ“… Published: March 19, 2026, 9:49 p.m. πŸ”„ Last Modified: March 20, 2026, 4:27 p.m.

2.3

CVSS4.0

CVE-2026-28282 - Discourse vulnerable to group membership addition permission bypass via discourse-policy plugin

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any private/restricted groups. Once membership to a priv…

πŸ“… Published: March 19, 2026, 9:45 p.m. πŸ”„ Last Modified: March 20, 2026, 5:01 p.m.
Total resulsts: 339290
Page 55 of 33,929
Β« previous page Β» next page
Filters