CVE-2025-68659 | Discourse prior 3.5.4/2025.11.2/2025.12.1/2026.1.0 Username Preference Endpoint /u//preferences/username allocation of resources (GHSA-rmp6-c9rq-6q7p / EUVD-2025-206425)
A vulnerability classified as problematic was found in Discourse. Affected by this vulnerability is an unknown functionality of the file /u//preferences/username of the component Username Preference Endpoint. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-68659. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.