CVE Vulnerabilities

CVE-2025-61598

Use of Cache Containing Sensitive Information

Published: Oct 28, 2025 | Modified: Dec 03, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This vulnerability is fixed in 3.6.2 and 3.6.0.beta2.

Weakness

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Discourse Discourse * 3.5.2 (excluding)
Discourse Discourse * 3.6.0 (excluding)
Discourse Discourse 3.6.0-beta1 (including) 3.6.0-beta1 (including)

Potential Mitigations

References