Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares hostnames and SiteSetting.blocked_onebox_domains entries case-sensitively, allowing an attacker to bypass configured Onebox domain restrictions by changing character casing in a redirect target hostname. This issue is fixed in versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0.
CVE-2026-72721
This medium-severity CVE scores 5.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.6% (46th percentile of EPSS-scored CVEs). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- Lower severity and no public exploit yet
The CVE record names the fixed release — apply it.
- CVSS v3
- 5.3
- EG Score
- 5.3MEDIUMmedium confidence
- EG Risk
- 39EG Risk 39/100CISA SSVC
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity53% × 45%Exploitation1% × 40%Automatability100% × 15%CISA SSVC: Track at low or medium mission impact; Attend at high (mission-essential systems).Action: The CVE record names the fixed release. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high. - EPSS PROB
- 0.6%
- EPSS %ILE
- 46th
- KEV
- Not listed
CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).
The CVE record names the fixed release. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table
Published
August 10, 2026
Last Modified
September 8, 2026
Advisory Details (9)
Auto-updated Aug 10, 2026Onebox Domain Blocklist Bypass via Case-Sensitive Comparison · Advisory · discourse/discourse · GitHub
https://github.com/discourse/discourse/security/advisories/GHSA-3x7x-24rq-h5j6Security fixes for release/2026.6
Fix merged in discourse/discourse PR #42094 on 2026-07-28 — awaiting tagged release
https://github.com/discourse/discourse/pull/42094Security fixes for release/2026.5
Fix merged in discourse/discourse PR #42093 on 2026-07-28 — awaiting tagged release
https://github.com/discourse/discourse/pull/42093Security fixes for release/2026.1
Fix merged in discourse/discourse PR #42092 on 2026-07-28 — awaiting tagged release
https://github.com/discourse/discourse/pull/42092Security fixes for main
Fix merged in discourse/discourse PR #42091 on 2026-07-28 — awaiting tagged release
https://github.com/discourse/discourse/pull/42091commit f503971d311b (discourse/discourse)
Fix landed in discourse/discourse commit f503971d311b — awaiting tagged release
https://github.com/discourse/discourse/commit/f503971d311b7b0dfdb751ee8cfd67e8cb99f5c5commit caa615c371b1 (discourse/discourse)
Fix landed in discourse/discourse commit caa615c371b1 — awaiting tagged release
https://github.com/discourse/discourse/commit/caa615c371b1696982ee11ac8f3558f0f8ced584commit c2eb6b0e5597 (discourse/discourse)
Fix landed in discourse/discourse commit c2eb6b0e5597 — awaiting tagged release
https://github.com/discourse/discourse/commit/c2eb6b0e5597d6f28f4be739b83300bc9c69e3cdcommit a3e10759fef4 (discourse/discourse)
Fix landed in discourse/discourse commit a3e10759fef4 — awaiting tagged release
https://github.com/discourse/discourse/commit/a3e10759fef47f03d450649bb51d9e84f4c68b8fWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 10× in last 7d / 40× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-10-09 20:07 UTCEPSS rescore
- 2026-10-08 17:13 UTCEPSS rescore
- 2026-10-07 23:48 UTCEPSS rescore
- 2026-10-06 18:21 UTCEG score recompute
- 2026-10-06 15:18 UTCEPSS rescore
- 2026-10-05 17:43 UTCEPSS rescore
- 2026-10-05 07:48 UTCEG score recompute
- 2026-10-04 23:22 UTCEPSS rescore
- 2026-10-04 04:26 UTCEG score recompute
- 2026-10-03 14:26 UTCEPSS rescore
- 2026-10-02 09:19 UTCEG score recompute
- 2026-10-01 19:50 UTCEPSS rescore
- 2026-09-30 22:36 UTCEG score recompute
- 2026-09-29 05:22 UTCEG score recompute
- 2026-09-28 13:52 UTCEPSS rescore
- 2026-09-27 13:48 UTCEPSS rescore
- 2026-09-27 12:45 UTCEG score recompute
- 2026-09-26 15:59 UTCEPSS rescore
- 2026-09-25 04:01 UTCEG score recompute
- 2026-09-23 21:10 UTCEG score recompute
- 2026-09-23 17:54 UTCEPSS rescore
- 2026-09-22 15:23 UTCEG score recompute
- 2026-09-21 21:09 UTCEPSS rescore
- 2026-09-21 13:05 UTCEG score recompute
- 2026-09-20 20:16 UTCEPSS rescore
Show 74 moreShow fewer
- 2026-09-20 10:48 UTCEG score recompute
- 2026-09-19 05:19 UTCEG score recompute
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-18 03:02 UTCEG score recompute
- 2026-09-17 00:45 UTCEG score recompute
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-16 05:15 UTCEPSS rescore
- 2026-09-15 13:46 UTCEG score recompute
- 2026-09-15 03:12 UTCEPSS rescore
- 2026-09-14 11:09 UTCEG score recompute
- 2026-09-13 08:53 UTCEG score recompute
- 2026-09-12 15:02 UTCEPSS rescore
- 2026-09-12 06:36 UTCEG score recompute
- 2026-09-11 14:53 UTCEPSS rescore
- 2026-09-11 04:18 UTCEG score recompute
- 2026-09-10 09:35 UTCEPSS rescore
- 2026-09-10 02:01 UTCEG score recompute
- 2026-09-08 22:01 UTCEPSS rescore
- 2026-09-07 17:17 UTCEG score recompute
- 2026-09-06 13:48 UTCEPSS rescore
- 2026-09-06 12:57 UTCEG score recompute
- 2026-09-05 10:40 UTCEG score recompute
- 2026-09-04 08:22 UTCEG score recompute
- 2026-09-04 05:07 UTCEPSS rescore
- 2026-09-03 03:07 UTCEG score recompute
- 2026-09-02 14:12 UTCEPSS rescore
- 2026-09-02 00:45 UTCEG score recompute
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-09-01 04:40 UTCEPSS rescore
- 2026-08-31 22:11 UTCEG score recompute
- 2026-08-30 19:18 UTCEPSS rescore
- 2026-08-30 19:17 UTCEPSS rescore
- 2026-08-30 12:15 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 09:58 UTCEG score recompute
- 2026-08-28 21:42 UTCEPSS rescore
- 2026-08-28 06:21 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-27 03:59 UTCEG score recompute
- 2026-08-26 14:47 UTCEPSS rescore
- 2026-08-26 01:41 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-24 23:25 UTCEG score recompute
- 2026-08-23 21:08 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 18:51 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 16:34 UTCEG score recompute
- 2026-08-20 22:56 UTCEPSS rescore
- 2026-08-20 14:17 UTCEG score recompute
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-19 11:37 UTCEG score recompute
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 13:49 UTCEPSS rescore
- 2026-08-18 09:20 UTCEG score recompute
- 2026-08-17 13:47 UTCEPSS rescore
- 2026-08-17 07:04 UTCEG score recompute
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 14:56 UTCEPSS rescore
- 2026-08-16 04:47 UTCEG score recompute
- 2026-08-16 02:15 UTCEPSS rescore
- 2026-08-15 02:29 UTCEG score recompute
- 2026-08-15 01:31 UTCEPSS rescore
- 2026-08-14 00:13 UTCEG score recompute
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-12 21:55 UTCEG score recompute
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-11 19:38 UTCEG score recompute
- 2026-08-10 17:22 UTCEG score recompute
- 2026-08-10 17:10 UTCEG score recompute
- 2026-08-10 16:29 UTCEG score recompute
- 2026-08-10 16:10 UTCEG score recompute
- 2026-08-10 16:09 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-72721?
When was CVE-2026-72721 disclosed?
Is CVE-2026-72721 actively exploited?
What is the CVSS score of CVE-2026-72721?
How do I remediate CVE-2026-72721?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-72721
Is Your Infrastructure Affected by CVE-2026-72721?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.