Junglewise Threat Intelligence

CVE-2026-72721: Discourse Onebox domain blocklist bypass via case-sensitive comparison

CVE-2026-72721 · Severity: medium · CVSS 5.3 · Published 2026-08-10

Technologies: Discourse. Vendors: Discourse.

Executive brief

Discourse is an open-source discussion platform that allows administrators to configure a blocklist of domains that should not be embedded as Onebox previews. A case-sensitive string comparison flaw in the blocklist check allows attackers to bypass these restrictions by altering the character casing of blocked domain names in redirect URLs, potentially exposing users to malicious or unwanted content.

Technical details

The vulnerability exists in Discourse's Onebox::DomainChecker.is_blocked? method, which performs case-sensitive string matching when comparing hostnames against the SiteSetting.blocked_onebox_domains blocklist. An attacker can exploit this by crafting a redirect that uses different character casing (e.g., example.COM instead of example.com) to bypass the configured domain restrictions. The fix normalizes hostname comparisons to case-insensitive matching. The vulnerability requires no authentication and is exploitable by any user capable of posting content with embedded links, but relies on a redirect target using different casing than the blocklist entry.

Affected products

  • Discourse Discourse prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Patches released for versions 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0

References

Related threats