Unrated severityOSV Advisory· Published Jan 28, 2026· Updated Jan 28, 2026
FinalDestination hostname matching allows SSRF protection bypass
CVE-2025-68662
Description
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available.
Affected products
1- Range: beta, latest-release, release, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/discourse/discourse/security/advisories/GHSA-gcfp-rjfc-925cmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.