Resource exhaustion in Discourse - CVE-2023-41042
Published: September 13, 2023 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in remote theme asset importing when loading remote theme assets into memory. A remote privileged user can import a remote theme with excessive asset size or file count to cause a denial of service.