Security patch on the 2026.7 ESR line (Discourse ships YYYY.M.patch calver). The recipe moved
from bitnamilegacy to the official discourse/discourse image upstream; this PR only bumps the app
image tag. No version label bump — the operator publishes with the release command at the bottom.
Image tag table
service
image
current
new
action
app
discourse/discourse
2026.7.2
2026.7.3
bumped
db
discourse/postgres
pg18
pg18
held (already newest)
redis
redis
8.10-alpine
8.10-alpine
held (already newest)
Held-services rationale:
redis — abra reports no newer version for the pinned 8.10-alpine; 8.10.2-alpine exists but
the recipe intentionally tracks the floating 8.10-alpine minor line, and abra's -m check finds
no bump. Left as-is.
db — discourse/postgres tags are pg<MAJOR> (non-semver), which abra cannot parse
(WARN unable to parse discourse/postgres … skipping upgrade for db). Direct Docker Hub check
(2026-09-28) shows the newest tag is pg18, which is what we already pin — no pg19 yet. Held.
Sidecars unchanged this PR, so no upstream notes to link for them.
Operator Action Required
This is a security patch release (Discourse's 2026-09-22 intermediate release; 3 new security
fixes, all rated High). Nothing here is a hard break for the recipe boot: Rails migrations run
automatically on first boot of the new image, there are no new/renamed env vars, no compose/config
changes, and no recipe code changes — the image tag is the whole diff.
The three CVEs fixed by moving to 2026.7.3:
CVE-2026-91156 (GHSA-gh4f-qr62-vx8q, CVSS 7.5 High) — Chat MessageBus delivers read-restricted
messages to unauthorized users. On sites where Chat access is restricted by group, a user who can
view a read-restricted category (but is not allowed to use Chat) could receive that category's chat
content via the MessageBus live/backlog. Workaround if upgrade is delayed: remove the disallowed
user from the category, or avoid the affected category/chat combination. https://github.com/discourse/discourse/security/advisories/GHSA-gh4f-qr62-vx8q
CVE-2026-91157 (GHSA-298h-xgw6-4pv3, CVSS 7.5 High) — Media uploads remain publicly
accessible after category permissions are restricted. Only affects sites with secure uploads
enabled: uploads posted while a category was public keep a public flag and stay reachable by
anonymous users at their short URLs after the category becomes read-restricted. Workaround if
upgrade is delayed: download+re-upload affected media through a restricted context, or delete the
affected uploads. Operators who have ever tightened a category from public → restricted should
treat this as the priority fix in this release. https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3
CVE-2026-91159 (GHSA-f9jx-vv33-4282, CVSS 7.7 High) — Stored oEmbed HTML injection via
allowlisted iframe. A regular user with posting rights could inject attacker-controlled HTML/CSS
into posts through oEmbed processing (an allowlisted iframe plus sibling elements), enabling
stored phishing/overlay content. No CSP interaction required. No full workaround short of upgrading
(optionally trim the iframe allowlist). https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282
One advisory could not be version-classified and is recorded as STILL-UNKNOWN, not
unaffected: CVE-2025-53016 (low) — HTML injection in solved posts when display_name_on_posts is
enabled; the advisory publishes no patched version (open-ended < commit range), so this window
cannot be shown to fix it. https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h
Advisory scan: 3 CVEs fixed by this upgrade (CVE-2026-91156/91157/91159, all High) + 1
STILL-UNKNOWN (CVE-2025-53016, low). Release-note reading agrees (changelog "3 security fixes").
Recommended release command
Leave the version label as-is; after this PR merges, publish with:
abra recipe release discourse -z
(patch/security release within the same ESR line → -z. No --dry-run — this performs the real
release: bumps the coop-cloud.${STACK_NAME}.version label, tags, and pushes.)
Verification
Direct --chaos deploy of this PR head on the cc-ci swarm (dev-discourse.ci.commoninternet.net)
converged: discourse/discourse:2026.7.3 booted, compiled CSS, ran migrations, started
unicorn/pitchfork + supervised sidekiqs, and passed its healthcheck (healthy). Dev deploy torn
down after inspection.
abra recipe lint discourse -C -n: no error-severity failures (pre-existing warnings only:
R005 semver-like tags for pg18/8.10-alpine, R015 secret-name length).
Guardrails
NOT merged — recipe PR only, for operator review. No cc-ci test/harness changes (DEFAULT mode).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
## Recipe upgrade: discourse `2026.7.2 → 2026.7.3`
Security patch on the **2026.7 ESR** line (Discourse ships `YYYY.M.patch` calver). The recipe moved
from bitnamilegacy to the official `discourse/discourse` image upstream; this PR only bumps the app
image tag. **No version label bump** — the operator publishes with the release command at the bottom.
### Image tag table
| service | image | current | new | action |
|---|---|---|---|---|
| app | `discourse/discourse` | `2026.7.2` | `2026.7.3` | **bumped** |
| db | `discourse/postgres` | `pg18` | `pg18` | held (already newest) |
| redis | `redis` | `8.10-alpine` | `8.10-alpine` | held (already newest) |
Held-services rationale:
- **redis** — abra reports no newer version for the pinned `8.10-alpine`; `8.10.2-alpine` exists but
the recipe intentionally tracks the floating `8.10-alpine` minor line, and abra's `-m` check finds
no bump. Left as-is.
- **db** — `discourse/postgres` tags are `pg<MAJOR>` (non-semver), which abra cannot parse
(`WARN unable to parse discourse/postgres … skipping upgrade for db`). Direct Docker Hub check
(2026-09-28) shows the newest tag is `pg18`, which is what we already pin — no `pg19` yet. Held.
### Upstream release notes
**Upstream release notes:** app `discourse/discourse` 2026.7.2 → 2026.7.3: https://releases.discourse.org/changelog/v2026.7.3/
- GitHub compare (39 commits, release/2026.7 backports): https://github.com/discourse/discourse/compare/v2026.7.2...v2026.7.3
- Registry: https://releases.discourse.org/ (per-version changelogs)
- Release announcement (September 2026 monthly release + patches): https://meta.discourse.org/t/september-2026-monthly-release/413037
Sidecars unchanged this PR, so no upstream notes to link for them.
### Operator Action Required
This is a **security patch release** (Discourse's 2026-09-22 intermediate release; 3 new security
fixes, all rated High). Nothing here is a hard break for the recipe boot: Rails migrations run
automatically on first boot of the new image, there are **no new/renamed env vars, no compose/config
changes, and no recipe code changes** — the image tag is the whole diff.
The three CVEs fixed by moving to 2026.7.3:
- **CVE-2026-91156** (GHSA-gh4f-qr62-vx8q, CVSS 7.5 High) — *Chat MessageBus delivers read-restricted
messages to unauthorized users.* On sites where Chat access is restricted by group, a user who can
view a read-restricted category (but is not allowed to use Chat) could receive that category's chat
content via the MessageBus live/backlog. Workaround if upgrade is delayed: remove the disallowed
user from the category, or avoid the affected category/chat combination.
https://github.com/discourse/discourse/security/advisories/GHSA-gh4f-qr62-vx8q
- **CVE-2026-91157** (GHSA-298h-xgw6-4pv3, CVSS 7.5 High) — *Media uploads remain publicly
accessible after category permissions are restricted.* Only affects sites with **secure uploads
enabled**: uploads posted while a category was public keep a public flag and stay reachable by
anonymous users at their short URLs after the category becomes read-restricted. Workaround if
upgrade is delayed: download+re-upload affected media through a restricted context, or delete the
affected uploads. **Operators who have ever tightened a category from public → restricted should
treat this as the priority fix in this release.**
https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3
- **CVE-2026-91159** (GHSA-f9jx-vv33-4282, CVSS 7.7 High) — *Stored oEmbed HTML injection via
allowlisted iframe.* A regular user with posting rights could inject attacker-controlled HTML/CSS
into posts through oEmbed processing (an allowlisted iframe plus sibling elements), enabling
stored phishing/overlay content. No CSP interaction required. No full workaround short of upgrading
(optionally trim the iframe allowlist).
https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282
One advisory could **not** be version-classified and is recorded as **STILL-UNKNOWN**, not
unaffected: **CVE-2025-53016** (low) — HTML injection in solved posts when `display_name_on_posts` is
enabled; the advisory publishes no patched version (open-ended `< commit` range), so this window
cannot be shown to fix it. https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h
Advisory scan: **3 CVEs fixed by this upgrade** (CVE-2026-91156/91157/91159, all High) + 1
STILL-UNKNOWN (CVE-2025-53016, low). Release-note reading agrees (changelog "3 security fixes").
### Recommended release command
Leave the version label as-is; after this PR merges, publish with:
```
abra recipe release discourse -z
```
(patch/security release within the same ESR line → `-z`. **No `--dry-run`** — this performs the real
release: bumps the `coop-cloud.${STACK_NAME}.version` label, tags, and pushes.)
### Verification
- Direct `--chaos` deploy of this PR head on the cc-ci swarm (`dev-discourse.ci.commoninternet.net`)
converged: `discourse/discourse:2026.7.3` booted, compiled CSS, ran migrations, started
unicorn/pitchfork + supervised sidekiqs, and passed its healthcheck (`healthy`). Dev deploy torn
down after inspection.
- `abra recipe lint discourse -C -n`: no error-severity failures (pre-existing warnings only:
R005 semver-like tags for `pg18`/`8.10-alpine`, R015 secret-name length).
### Guardrails
**NOT merged** — recipe PR only, for operator review. No cc-ci test/harness changes (DEFAULT mode).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Recipe upgrade: discourse
2026.7.2 → 2026.7.3Security patch on the 2026.7 ESR line (Discourse ships
YYYY.M.patchcalver). The recipe movedfrom bitnamilegacy to the official
discourse/discourseimage upstream; this PR only bumps the appimage tag. No version label bump — the operator publishes with the release command at the bottom.
Image tag table
discourse/discourse2026.7.22026.7.3discourse/postgrespg18pg18redis8.10-alpine8.10-alpineHeld-services rationale:
8.10-alpine;8.10.2-alpineexists butthe recipe intentionally tracks the floating
8.10-alpineminor line, and abra's-mcheck findsno bump. Left as-is.
discourse/postgrestags arepg<MAJOR>(non-semver), which abra cannot parse(
WARN unable to parse discourse/postgres … skipping upgrade for db). Direct Docker Hub check(2026-09-28) shows the newest tag is
pg18, which is what we already pin — nopg19yet. Held.Upstream release notes
Upstream release notes: app
discourse/discourse2026.7.2 → 2026.7.3: https://releases.discourse.org/changelog/v2026.7.3/Sidecars unchanged this PR, so no upstream notes to link for them.
Operator Action Required
This is a security patch release (Discourse's 2026-09-22 intermediate release; 3 new security
fixes, all rated High). Nothing here is a hard break for the recipe boot: Rails migrations run
automatically on first boot of the new image, there are no new/renamed env vars, no compose/config
changes, and no recipe code changes — the image tag is the whole diff.
The three CVEs fixed by moving to 2026.7.3:
messages to unauthorized users. On sites where Chat access is restricted by group, a user who can
view a read-restricted category (but is not allowed to use Chat) could receive that category's chat
content via the MessageBus live/backlog. Workaround if upgrade is delayed: remove the disallowed
user from the category, or avoid the affected category/chat combination.
https://github.com/discourse/discourse/security/advisories/GHSA-gh4f-qr62-vx8q
accessible after category permissions are restricted. Only affects sites with secure uploads
enabled: uploads posted while a category was public keep a public flag and stay reachable by
anonymous users at their short URLs after the category becomes read-restricted. Workaround if
upgrade is delayed: download+re-upload affected media through a restricted context, or delete the
affected uploads. Operators who have ever tightened a category from public → restricted should
treat this as the priority fix in this release.
https://github.com/discourse/discourse/security/advisories/GHSA-298h-xgw6-4pv3
allowlisted iframe. A regular user with posting rights could inject attacker-controlled HTML/CSS
into posts through oEmbed processing (an allowlisted iframe plus sibling elements), enabling
stored phishing/overlay content. No CSP interaction required. No full workaround short of upgrading
(optionally trim the iframe allowlist).
https://github.com/discourse/discourse/security/advisories/GHSA-f9jx-vv33-4282
One advisory could not be version-classified and is recorded as STILL-UNKNOWN, not
unaffected: CVE-2025-53016 (low) — HTML injection in solved posts when
display_name_on_postsisenabled; the advisory publishes no patched version (open-ended
< commitrange), so this windowcannot be shown to fix it. https://github.com/discourse/discourse/security/advisories/GHSA-48h6-hpp2-357h
Advisory scan: 3 CVEs fixed by this upgrade (CVE-2026-91156/91157/91159, all High) + 1
STILL-UNKNOWN (CVE-2025-53016, low). Release-note reading agrees (changelog "3 security fixes").
Recommended release command
Leave the version label as-is; after this PR merges, publish with:
(patch/security release within the same ESR line →
-z. No--dry-run— this performs the realrelease: bumps the
coop-cloud.${STACK_NAME}.versionlabel, tags, and pushes.)Verification
--chaosdeploy of this PR head on the cc-ci swarm (dev-discourse.ci.commoninternet.net)converged:
discourse/discourse:2026.7.3booted, compiled CSS, ran migrations, startedunicorn/pitchfork + supervised sidekiqs, and passed its healthcheck (
healthy). Dev deploy torndown after inspection.
abra recipe lint discourse -C -n: no error-severity failures (pre-existing warnings only:R005 semver-like tags for
pg18/8.10-alpine, R015 secret-name length).Guardrails
NOT merged — recipe PR only, for operator review. No cc-ci test/harness changes (DEFAULT mode).
Tested green on the cc-ci recipe CI server (full suite, cold, against this PR head). NOT merged — for operator review.
cc @trav @notplants
!testme
🌻 cc-ci —
discourse@3f2384fd✅ passedfull logs · dashboard
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.