CVE-2026-33422: Discourse exposes ip_address of flagged user
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the ipaddress of a flagged user is exposed to any user who can access the review queue, including users who should not be able to see IP addresses. Versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 contain a patch. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33422?
CVE-2026-33422 has been categorized with a medium severity level due to the risk of exposing sensitive user information.
How do I fix CVE-2026-33422?
To fix CVE-2026-33422, upgrade to version 2026.3.0-latest.1 or later, 2026.2.1 or later, or 2026.1.2 or later of Discourse.
Which versions of Discourse are affected by CVE-2026-33422?
CVE-2026-33422 affects Discourse versions up to and including 2026.3.0-latest.1, 2026.2.1, and 2026.1.2.
What type of information is exposed in CVE-2026-33422?
CVE-2026-33422 exposes the IP addresses of flagged users to unauthorized individuals who can access the review queue.
Who is impacted by CVE-2026-33422?
Users who can access the review queue in Discourse prior to the patched versions are impacted by CVE-2026-33422.