CVE-2026-53961 Details
Description
Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, the AWS SES bounce webhook at POST /webhooks/aws verified that SNS messages were signed by Amazon but did not bind them to trusted TopicArn values, allowing any AWS account holder to publish validly signed forged Bounce notifications that revoke a targeted user email. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.
A vulnerability in Discourse's handling of AWS SNS messages can be exploited to forge bounce notifications that affect user email accounts. This issue is present in Discourse versions prior to 2026.6.0, as well as in versions 2026.5.1, 2026.4.2, and 2026.1.5. The vulnerability arises because the AWS SES bounce webhook does not verify that SNS messages come from trusted topics. As a result, any AWS account holder can send validly signed but fake bounce notifications that revoke a targeted user's email, disrupting their ability to receive notifications and password-reset emails.
Users can update to Discourse versions 2026.6.0, 2026.5.1, 2026.4.2, or 2026.1.5. After updating, it's recommended to configure the 'aws_sns_topic_arn_allowlist' setting to include only trusted SNS topic ARNs.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| discourse discourse | >= 2026.1.0, < 2026.1.5 >= 2026.4.0, < 2026.4.2 >= 2026.5.0, < 2026.5.1 2026.6.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | Initial Analysis | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |