CVE-2021-43794
Status: ModifiedMedium (5.3)—
Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is patched in the latest stable, beta and tests-passed versions of Discourse.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.05%
- Percentile among all scored CVEs: 63
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-610
References
- https://github.com/discourse/discourse/commit/2da0001965c6d8632d723c46ea5df9f22a1a23f1
- https://github.com/discourse/discourse/security/advisories/GHSA-249g-pc77-65hp
- https://github.com/discourse/discourse/commit/2da0001965c6d8632d723c46ea5df9f22a1a23f1
- https://github.com/discourse/discourse/security/advisories/GHSA-249g-pc77-65hp
Raw JSON (NVD)
Show
{
"id": "CVE-2021-43794",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "discourse",
"product": "discourse",
"versions": [
{
"status": "affected",
"version": "stable < 2.7.11"
},
{
"status": "affected",
"version": "beta < 2.8.0.beta9"
},
{
"status": "affected",
"version": "tests-passed < 2.8.0.beta9"
}
]
}
]
}
],
"published": "2021-12-01T20:15:08.727",
"references": [
{
"url": "https://github.com/discourse/discourse/commit/2da0001965c6d8632d723c46ea5df9f22a1a23f1",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/discourse/discourse/security/advisories/GHSA-249g-pc77-65hp",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/discourse/discourse/commit/2da0001965c6d8632d723c46ea5df9f22a1a23f1",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/discourse/discourse/security/advisories/GHSA-249g-pc77-65hp",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-610"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.e. not logged in) users, such that the users are shown a JSON blob instead of the HTML page. This can lead to a partial denial-of-service. This issue is patched in the latest stable, beta and tests-passed versions of Discourse."
},
{
"lang": "es",
"value": "Discourse es una plataforma de debate de código abierto. En las versiones afectadas, un atacante puede envenenar la caché de los usuarios anónimos (es decir, los que no han iniciado sesión), de forma que se les muestre un blob JSON en lugar de la página HTML. Esto puede conllevar a una denegación de servicio parcial. Este problema está parcheado en las últimas versiones estables, beta y de prueba de Discourse"
}
],
"lastModified": "2026-06-17T04:11:27.187",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:discourse:discourse:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F845CD5-5BBB-4686-B459-F20DEC41748C",
"versionEndExcluding": "2.7.11"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}