CVE-2025-48053: Discourse vulnerable to DoS via large URL payload in PM to a bot
Discourse is an open-source discussion platform. Prior to version 3.4.4 of the stable branch, version 3.5.0.beta5 of the beta branch, and version 3.5.0.beta6-dev of the tests-passed branch, sending a malicious URL in a PM to a bot user can cause a reduced the availability of a Discourse instance. This issue is patched in version 3.4.4 of the stable branch, version 3.5.0.beta5 of the beta branch, and version 3.5.0.beta6-dev of the tests-passed branch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48053?
CVE-2025-48053 has a high severity due to the potential for reduced availability when handling malicious URLs.
How do I fix CVE-2025-48053?
To fix CVE-2025-48053, update to Discourse version 3.4.4 or newer on the stable branch, or version 3.5.0.beta5 or newer on the beta branch.
What versions are affected by CVE-2025-48053?
CVE-2025-48053 affects Discourse versions earlier than 3.4.4 on the stable branch and versions prior to 3.5.0.beta5 on the beta branch.
What type of vulnerability is CVE-2025-48053?
CVE-2025-48053 is a security vulnerability that can lead to denial of service through manipulation of private messages.
Who is impacted by CVE-2025-48053?
Users of Discourse prior to the specified versions are at risk from CVE-2025-48053, especially if interacting with bot users.