
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68662 is a Server-Side Request Forgery (SSRF) protection bypass vulnerability in Discourse, an open-source discussion platform. A hostname validation flaw in the FinalDestination component allows authenticated attackers with low privileges to circumvent SSRF protections under certain conditions. Affected versions include all Discourse releases prior to 3.5.4 (stable track), 2025.11.2, 2025.12.1, and 2026.1.0. The vulnerability was published on January 28, 2026. The GitHub Security Advisory assigns a CVSS v3.1 score of 7.6 (High), while Feedly's aggregated data reflects a score of 9.9 (Critical) based on a changed-scope vector (GitHub Advisory, Red Hat CVE).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from improper hostname validation in Discourse's FinalDestination class, which is responsible for resolving and fetching remote URLs. Under certain conditions, the hostname matching logic can be bypassed, allowing crafted requests to reach internal network destinations that should be blocked by SSRF protections. The attack vector is network-based, requires low privileges (an authenticated user account), no user interaction, and has low attack complexity. No public proof-of-concept or detailed technical write-up describing the exact bypass mechanism has been published as of the disclosure date (GitHub Advisory).
Successful exploitation allows an authenticated attacker to make the Discourse server issue requests to internal network resources, potentially exposing sensitive internal services, metadata endpoints (e.g., cloud provider IMDS), or other infrastructure not intended to be publicly accessible. The GitHub advisory rates confidentiality impact as High, with low integrity and availability impact; the broader CVSS estimate with changed scope elevates all three to High. This could facilitate lateral movement within internal networks, credential theft from cloud metadata services, or unauthorized interaction with backend systems (GitHub Advisory, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.038%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA referenced it in a weekly vulnerability bulletin. No threat actor attribution has been reported (GitHub Advisory, CISA Bulletin).
FinalDestination — for example, using techniques such as DNS rebinding, URL encoding tricks, or special hostname formats that bypass the blocklist/allowlist checks.FinalDestination (e.g., link previews, onebox embedding, or similar URL-fetching functionality).http://169.254.169.254/), internal APIs, or other restricted hosts, and may return sensitive data in the response (GitHub Advisory).FinalDestination fetch attempts to internal or loopback addresses; repeated URL fetch requests from a single low-privilege user account targeting non-public URLs.Discourse has released patched versions addressing this vulnerability: 3.5.4 (stable legacy track), 2025.11.2 (2025.11.x series), 2025.12.1 (2025.12.x series), and 2026.1.0 (2026.1.x series). Administrators should upgrade to the appropriate patched version immediately. No configuration-based workarounds are available; upgrading is the only remediation (GitHub Advisory).
The vulnerability received brief coverage on social media platforms including Mastodon and Bluesky via security news accounts such as TheHackerWire, and was noted in CISA's weekly vulnerability bulletin for the week of January 26, 2026. No significant vendor statements beyond the GitHub Security Advisory or notable independent researcher commentary have been published (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."