Discourse Hostname Validation Vulnerability in FinalDestination Allows SSRF Protection Bypass

Vulnerability

A vulnerability in Discourse's hostname validation within the FinalDestination component could lead to bypassing Server-Side Request Forgery (SSRF) protections, under certain conditions. This issue affects Discourse versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0.

Impact

Exploitation of this vulnerability could allow an attacker to bypass SSRF protections, potentially leading to unauthorized access to internal services or resources.

Remediation

Users are advised to upgrade to Discourse versions 3.5.4, 2025.11.2, 2025.12.1, or 2026.1.0.

Added: Jan 28, 2026, 8:26 PM
Updated: Jan 28, 2026, 8:26 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
0.6
exploitability
2.7
remediation
7.7
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.