Improper Handling of Case Sensitivity in Discourse - #VU140007
Published: July 29, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the Onebox domain blocklist comparison logic when processing redirect targets. A remote attacker can use case variations in a hostname to bypass domain restrictions and disclose sensitive information.