CVE-2026-59828: Discourse: Hidden post revisions leak through adjacent visible diffs
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions that should be hidden from regular users could be leaked through visible diffs on adjacent revisions serialized by PostRevisionSerializer. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.6.0 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.5.1 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.4.2 - Upgrade
Upgrade
Discourseto a version that resolves this vulnerability.Fixed in 2026.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59828?
The severity of CVE-2026-59828 is rated as medium with a score of 5.3.
How do I fix CVE-2026-59828?
To fix CVE-2026-59828, upgrade to versions 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5 of Discourse.
What type of vulnerability is CVE-2026-59828?
CVE-2026-59828 is an information leak vulnerability affecting Discourse.
What can be leaked in CVE-2026-59828?
CVE-2026-59828 allows hidden post revisions to be leaked through visible diffs on adjacent revisions.
What software is affected by CVE-2026-59828?
CVE-2026-59828 affects the Discourse open-source discussion platform.