Vulnerabilities
CVE-2025-68662 - FinalDestination hostname matching allows SSRF protection bypass
CVE ID : CVE-2025-68662 Published : Jan. 28, 2026, 8:16 p.m. | 44 minutes ago Description : Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostname validation issue in FinalDestination could allow bypassing SSRF protections under certain conditions. This issue is patched in versions 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0. No known workarounds are available. Severity: 7.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...