Executive brief
Discourse is an open-source platform used for hosting online discussion forums and communities. A security flaw in the group email settings allows certain users to force the server to connect to internal network addresses. This could allow an attacker to map out private internal infrastructure, probe cloud metadata services, or access other internal systems that are not intended to be reachable from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `test_email_settings` endpoint within the `GroupsController` of Discourse. The root cause is a lack of destination filtering and insufficient authorization checks, as the endpoint was accessible to non-staff group owners. An authenticated attacker with group owner privileges can provide arbitrary host and port combinations, causing the server to initiate outbound SMTP connections. This can be used to probe internal network infrastructure, cloud metadata endpoints, or other internal services. The issue has been addressed by restricting the endpoint to administrators and implementing IP-based filtering to block connections to private or internal addresses.
Affected products
- Discourse Discourse 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, 2026.3.0-latest to before 2026.3.0
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory
- 2026-03-31: patched