VYPR
Medium severity6.5NVD Advisory· Published Feb 8, 2023· Updated Jun 17, 2026

CVE-2023-25167

CVE-2023-25167

Description

Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised to upgrade. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <3.0.1
    • cpe:2.3:a:discourse:discourse:3.1.0:beta1:*:*:beta:*:*:*
    • (no CPE)
    • (no CPE)range: < 3.0.1
  • osv-coords
    Range: < 3.0.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.