Resource exhaustion in Discourse - CVE-2023-41043
Published: September 13, 2023 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in SvgSprite cache when bundling and caching theme component icon sprite uploads. A remote user can create a theme with a large number of theme components containing large icons-sprite uploads to cause a denial of service.
This issue only affects multisite installations.