文件
websafe-kb/08-threat-intel/registry/advisories/discourse--321c09b9ad.json

60 行
3.5 KiB
JSON

{
"canonical_id": "discourse--321c09b9ad",
"system_id": "discourse",
"display_name": "Discourse",
"category": "cms",
"advisory_mode": "core",
"title": "January 2026 Releases",
"summary": "<p>For more information on all the changes released in 2026.1, check out:</p>\n<aside class=\"onebox allowlistedgeneric\" data-onebox-src=\"https://releases.discourse.org/changelog/v2026.1.0/\">\n <header class=\"source\">\n <img src=\"https://d11a6trkgmumsb.cloudfront.net/optimized/3X/e/c/ecc92a52ee7353e03d5c0d1ea6521ce4541d9c25_2_500x500.png\" class=\"site-icon\" alt=\"\" data-dominant-color=\"6B6A4D\" width=\"500\" height=\"500\">\n\n <a href=\"https://releases.discourse.org/changelog/v2026.1.0/\" target=\"_blank\" rel=\"noopener\">releases.discourse.org</a>\n </header>\n\n <article class=\"onebox-body\">\n \n\n<h3><a href=\"https://releases.discourse.org/changelog/v2026.1.0/\" target=\"_blank\" rel=\"noopener\">v2026.1.0 Changelog | Discourse Releases</a></h3>\n\n <p>Featured changes and detailed commit history for Discourse 'v2026.1.0'.</p>\n\n\n </article>\n\n <div class=\"onebox-metadata\">\n \n \n </div>\n\n <div style=\"clear: both\"></div>\n</aside>\n\n<p>This is the first \u201cESR\u201d release of Discourse, and replaces the old \u201cstable\u201d branch. Sites tracking stable will be upgraded from 3.5 to 2026.1 on their next upgrade. To see all changes from 3.5 to 2026.1, <a href=\"https://releases.discourse.org/changelog/custom?end=v2026.1.0&amp;start=v3.5.3\">use this link</a>.</p>\n<p>Patch releases for other supported versions have also been released:</p>\n<ul>\n<li>\n<p><a href=\"https://releases.discourse.org/changelog/v2025.12.1\" class=\"inline-onebox\">v2025.12.1 Changelog | Discourse Releases</a></p>\n</li>\n<li>\n<p><a href=\"https://releases.discourse.org/changelog/v2025.11.2\" class=\"inline-onebox\">v2025.11.2 Changelog | Discourse Releases</a></p>\n</li>\n<li>\n<p><a href=\"https://releases.discourse.org/changelog/v3.5.4\" class=\"inline-onebox\">v3.5.4 Changelog | Discourse Releases</a></p>\n</li>\n</ul>\n <p><small>17 posts - 9 participants</small></p>\n <p><a href=\"https://meta.discourse.org/t/january-2026-releases/393903\">Read full topic</a></p>",
"published_at": "Wed, 28 Jan 2026 17:35:34 +0000",
"updated_at": "Wed, 28 Jan 2026 17:35:34 +0000",
"severity": "unknown",
"cvss_score": null,
"exploit_status": "unknown",
"source_confidence": "official",
"official_source_url": "https://meta.discourse.org/t/january-2026-releases/393903",
"secondary_source_urls": [],
"aliases": [],
"cve_ids": [],
"ghsa_ids": [],
"osv_ids": [],
"affected_versions": [],
"fixed_versions": [],
"package_name": null,
"render_markdown": false,
"case_path": null,
"secure_code_topics": [
"authz-server-side-recheck",
"xss-output-encoding",
"plugin-extension-trust-policy"
],
"status": "triage",
"triage_reasons": [
"missing affected/fixed version details"
],
"verification_status": "triage-manual",
"verification_mode": "synthetic",
"last_verified_at": null,
"last_run_id": null,
"evidence_bundle": null,
"historical_status": null,
"latest_status": null,
"browser_evidence": {
"required": false,
"present": false,
"refs": []
},
"repro_profile_id": "xss-generic",
"artifact_mode": "synthetic",
"blocked_reason": null,
"metadata": {
"source_names": [
"Discourse Release Notes RSS"
],
"source_kinds": [
"rss-feed"
],
"candidate_count": 1
}
}