
CVE-2026-33393 Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allowed_spam_host_domains` check used `String#end_w… https://www.cve.org/CVERecord?id=CVE-2026-33393
Post summary
The excerpt identifies a coding issue in Discourse’s spam host domain check, but provides only limited technical details and no evidence of exploitation or remediation.
