Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0902

NIXPKGS-2026-0902
published on
updated 1 month ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • discourse-mail-receiver
    • python312Packages.pydiscourse
    • python313Packages.pydiscourse
    • discourseAllPlugins
    • python314Packages.pydiscourse
    • grafanaPlugins.grafana-discourse-datasource
  • @LeSuisse restored package discourseAllPlugins
  • @LeSuisse deleted maintainer @talyz maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Discourse: Missing post-level authorization allows whisper metadata disclosure

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, non-staff users could access read receipt information for staff-only posts they weren't supposed to see. No post content was exposed, only metadata about who read the post and when. This issue has been patched in versions 2026.1.3, 2026.2.2, and 2026.3.0.

Affected products

discourse
  • ==>= 2026.1.0-latest, < 2026.1.3
  • ==>= 2026.2.0-latest, < 2026.2.2
  • ==>= 2026.3.0-latest, < 2026.3.0

Matching in nixpkgs

Ignored packages (5)

Package maintainers

Ignored maintainers (1)
https://github.com/discourse/discourse/security/advisories/GHSA-xgg2-vwr6-2c65