CVE-2025-24808

Discourse has race condition when adding users to a group DM

Discourse is an open-source discussion platform. Prior to versions `3.3.4` on the `stable` branch and `3.4.0.beta5` on the `beta` branch, someone who is about to reach the limit of users in a group DM may send requests to add new users in parallel. The requests might all go through ignoring the limit due to a race condition. The patch in versions `3.3.4` and `3.4.0.beta5` uses the `lock` step in service to wrap part of the `add_users_to_channel` service inside a distributed lock/mutex in order to avoid the race condition.


We have discovered 1,351 live websites that are affected by CVE-2025-24808.

Run a Free Instant Scan




Affected Software

Product  Discourse
Category Message Boards
Vulnerable Domains1,351 live websites (29% of Discourse install base)
Vulnerable Versions
  • from 0 through 3.3.4
  • from 3.4 through 3.4
Vulnerable Versions Count45 versions ( 79% of all versions)


Common Weakness Enumeration

CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')



Details

  • Published - Mar 26, 2025
  • Updated - Mar 26, 2025

Website Distribution by Country

Number of websites using CVE-2025-24808
United States829 websites



Germany130 websites
France64 websites
Singapore36 websites
China30 websites
GB24 websites
Russia24 websites
Japan21 websites
Brazil18 websites
Netherlands15 websites

Website Distribution by TLD

Number of websites using CVE-2025-24808
.com564 websites
.org207 websites
.io66 websites
.net58 websites
.de32 websites
.ru21 websites
.fr19 websites
.co17 websites
.eu15 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-24808

Top websites that are affected by CVE-2025-24808. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States**,***
*********.******.com United States**,***
******.********.com United States**,***
*********.***************.com United States**,***
**************.org United States***,***
*****.*******.com United States***,***
*****.******.com United States***,***
*********.**********.de Germany***,***
*****.*********.com United States***,***
*****.******.cloud United States***,***
See full domain list

FAQ

CVE-2025-24808 is Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in Discourse
A total of 1,351 websites have been identified as vulnerable to CVE-2025-24808, based on global website indexing conducted by WebTechSurvey.
The Discourse is affected by the CVE-2025-24808 vulnerability.
Discourse versions up to 3.4 are vulnerable to CVE-2025-24808.
CVE-2025-24808 is resolved in version 3.4 of Discourse.