CVE-2026-44782: Discourse

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, GroupPostSerializer declared include_user_long_name? as the predicate for its :name attribute, but AMS looks for include_name?. The misnamed predicate was never called, so object.user.name was always serialized regardless of SiteSetting.enable_names. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1.

Affected products

  • Discourse Discourse: before 2026.1.0 (fixed in 2026.1.0); from 2026.1.0, before 2026.1.4 (fixed in 2026.1.4); from 2026.3.0, before 2026.3.1 (fixed in 2026.3.1); from 2026.4.0, before 2026.4.1 (fixed in 2026.4.1); version 2026.5.0 only

Published 2026-06-12. Last modified 2026-06-17.