VYPR
Medium severity5.3OSV Advisory· Published Dec 30, 2025· Updated Jun 17, 2026

CVE-2025-64528

CVE-2025-64528

Description

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when enable_names is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • v0.8.0, v0.8.1, v0.8.2, …+ 4 more
    • (no CPE)range: v0.8.0, v0.8.1, v0.8.2, …
    • cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*range: <3.5.3
    • cpe:2.3:a:discourse:discourse:2025.11.0:*:*:*:stable:*:*:*
    • cpe:2.3:a:discourse:discourse:2025.12.0:*:*:*:stable:*:*:*
    • (no CPE)range: <3.5.3, <2025.11.1, <2025.12.0
  • osv-coords
    Range: < 3.5.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.