CVE Vulnerabilities

CVE-2025-61598

Use of Cache Containing Sensitive Information

Published: Oct 28, 2025 | Modified: Dec 03, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This vulnerability is fixed in 3.6.2 and 3.6.0.beta2.

Weakness

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Software

NameVendorStart VersionEnd Version
DiscourseDiscourse*3.5.2 (excluding)
DiscourseDiscourse*3.6.0 (excluding)
DiscourseDiscourse3.6.0-beta1 (including)3.6.0-beta1 (including)

Potential Mitigations

References