CVE-2023-36818: Discourse
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Discourse is an open source discussion platform. In affected versions a request to create or update custom sidebar section can cause a denial of service. This issue has been patched in commit `52b003d915`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected products
- Discourse Discourse: version 3.1.0 only
Published 2023-07-14. Last modified 2026-06-17.