# CVE-2025-61598

## Summary

- **CVE ID:** CVE-2025-61598
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-524
- **Published:** Oct 28, 2025
- **Last Modified:** Mar 12, 2026

## Description

Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those responses by proxies potentially leading to cache poisoning attacks. This vulnerability is fixed in 3.6.2 and 3.6.0.beta2.

## Affected Products

- discourse — discourse (< 3.6.2)
- discourse — discourse (>= 3.6.0.beta1, < 3.6.0.beta2)

## References

- [CNA](https://github.com/discourse/discourse/security/advisories/GHSA-jp9x-wwv6-cv3j)
- [CNA](https://github.com/discourse/discourse/commit/3ea1b663c82c067e5ca778db846bad1e082ba6cd)
- [CNA](https://github.com/discourse/discourse/commit/fd567af7bf5a15c70772021acbdf5d38487a31bc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.28%
- **EPSS Percentile:** 20.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._