CVE-2026-72721: Discourse: Onebox Domain Blocklist Bypass via Case-Sensitive Comparison
Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.isblocked? compares hostnames and SiteSetting.blockedoneboxdomains entries case-sensitively, allowing an attacker to bypass configured Onebox domain restrictions by changing character casing in a redirect target hostname. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.5.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.6.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72721?
The severity of CVE-2026-72721 is classified as medium with a score of 5.3.
How do I fix CVE-2026-72721?
To fix CVE-2026-72721, upgrade to the versions 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0 of Discourse.
What is the impact of CVE-2026-72721?
The impact of CVE-2026-72721 allows an attacker to bypass Onebox domain restrictions through case-sensitive hostname comparisons.
What software is affected by CVE-2026-72721?
CVE-2026-72721 affects the Discourse open-source discussion platform.
When was CVE-2026-72721 published?
CVE-2026-72721 was published on August 10, 2026.