Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.3.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.6.0-NA"
}
]
}