CVE-2026-31869 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest allowed_names information disclosure (GHSA-5f9h-vp7v-7vq5)
A vulnerability classified as problematic was found in Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest. The impacted element is the function allowed_names. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2026-31869. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.