Input validation error in Discourse - CVE-2023-40588
Published: September 13, 2023 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in 2fa and security key name handling when processing crafted 2fa or security key names. A remote user can add a 2fa or security key with a carefully crafted name to cause a denial of service.