CVE-2022-23548

MEDIUM6.5EPSS 0.64%
Published: 3/6/2024Modified: 10/14/2025
Also known as:GHSA-7rw2-f4x7-7pxfBIT-discourse-2022-23548

Description

Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched in version 2.8.14. There are no known workarounds.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

References (3)