Resource exhaustion in Discourse - CVE-2024-21655
Published: January 9, 2024 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in client-editable custom field values when processing oversized field data. A remote user can submit excessively large custom field values to cause a denial of service.
The issue can lead to excessive disk space consumption and often excessive bandwidth usage.