mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 13:08:40 +08:00
Backport of #41141 to release/2026.1. --- ## Summary The markdown engine generates poll options in an unbounded loop based on user input, enabling an attacker to trigger massive memory allocation and CPU usage in the V8 process. This blocks a global mutex and can cause worker crashes, effectively DoS-ing markdown processing for all users. ## Source - Patch Triage: https://patch.discourse.org/patch-triage/1120 - HackerOne report: https://hackerone.com/reports/3598542 --- 🤖 Auto-generated from the patch diff via Patch Triage. Review carefully before merging. Co-authored-by: discourse-patch-triage <272280883+discourse-patch-triage[bot]@users.noreply.github.com> Co-authored-by: Sam <sam.saffron@gmail.com> Co-authored-by: discourse-patch-triage[bot] <272280883+discourse-patch-triage[bot]@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| controllers | ||
| fabricators | ||
| integration | ||
| jobs/regular | ||
| lib | ||
| models | ||
| requests | ||
| serializers | ||
| system | ||