CVE Vulnerabilities

CVE-2025-64528

Exposure of Sensitive Information Through Data Queries

Published: Dec 30, 2025 | Modified: Feb 20, 2026
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Discourse is an open source discussion platform. Prior to versions 3.5.3, 2025.11.1, and 2025.12.0, an attacker who knows part of a username can find the user and their full name via UI or API, even when enable_names is disabled. Versions 3.5.3, 2025.11.1, and 2025.12.0 contain a fix.

Weakness

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Affected Software

NameVendorStart VersionEnd Version
DiscourseDiscourse*3.5.3 (excluding)
DiscourseDiscourse2025.11.0 (including)2025.11.0 (including)
DiscourseDiscourse2025.12.0 (including)2025.12.0 (including)

Potential Mitigations

References