CVE-2026-23743 | Discourse prior 3.5.4/2025.11.2/2025.12.1/2026.1.0 404 Page Search Box information disclosure (GHSA-v5jw-rxc6-4cvv / EUVD-2026-4861)
A vulnerability marked as problematic has been reported in Discourse. This impacts an unknown function of the component 404 Page Search Box. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2026-23743. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.