CVE Vulnerabilities

CVE-2025-64528

Exposure of Sensitive Information Through Data Queries

Published: Dec 30, 2025 | Modified: Dec 30, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when enable_names is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.

Weakness

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Potential Mitigations

References