Executive brief
Discourse is an open-source platform used for hosting online community discussions and forums. A vulnerability in how the platform handles email bounce notifications from Amazon Web Services (AWS) could allow an attacker to trick the system into thinking a user's email address is invalid. This results in the platform revoking the targeted user's email access, effectively preventing them from receiving forum notifications or resetting their passwords.
Technical details
A vulnerability exists in the Discourse AWS SES bounce webhook endpoint (`POST /webhooks/aws`) due to insufficient verification of data authenticity (CWE-345). While the application correctly verified that incoming Simple Notification Service (SNS) messages were cryptographically signed by Amazon, it failed to validate the `TopicArn` against an allowlist of trusted topics. An attacker with any valid AWS account could create their own SNS topic, subscribe the Discourse webhook to it, and send forged bounce notifications. This allows the attacker to increment the `bounce_score` for arbitrary email addresses, eventually leading to email revocation for targeted users. The fix introduces an `aws_sns_topic_arn_allowlist` setting and binds bounce processing to specific message and address identifiers.
Affected products
- Discourse Discourse < 2026.1.5, < 2026.4.2, < 2026.5.1, < 2026.6.0
Timeline
- 2026-06-30: patched: Fixes committed to various branches
- 2026-07-09: disclosed: Public advisory published
References
- https://github.com/discourse/discourse/commit/3a3d315a85ef3c6aabfc7e7bb38702059784f06b
- https://github.com/discourse/discourse/commit/61f12e13aa1b760f81d5ff60f12e3a7e77434b94
- https://github.com/discourse/discourse/commit/958f0cd831d65a49ec75f05343ca2c167679f0ea
- https://github.com/discourse/discourse/commit/aea35190791261bab258ebab05da279e78cdd0e6
- https://github.com/discourse/discourse/releases/tag/v2026.1.5
- https://github.com/discourse/discourse/releases/tag/v2026.4.2
- https://github.com/discourse/discourse/releases/tag/v2026.5.1