← Back to Versions

v2026.1.0-latestv2026.1.0

Highlights

High context topic cards

Our Horizon theme now supports a new, experimental option to show high context topic cards, with additional information for tags, assignments, solutions, and topic votes.

Jan 24, 2026 (bb235b5) Learn more →
High context topic cards

Use "Hot" as default topic list for categories

Admins can now configure "Hot" to be the default topic list for individual categories.

Jan 24, 2026 (1c90b0d)
Use "Hot" as default topic list for categories

New site for releases and changelogs

A new releases.discourse.org site is now available where you can see changelogs for Discourse, including upcoming and past releases.

Jan 24, 2026 (2026.1.0) Learn more →
New site for releases and changelogs

Carousel display for images in posts

When you include multiple images in a post, you can now choose between displaying them in a grid or in a new carousel mode. Switching is as simple as selecting the option in the top-right corner of the gallery in the rich text editor.

Jan 24, 2026 (dc21ce0) Learn more →
Carousel display for images in posts

Access common chat channel actions from the sidebar context menu

We’ve made it easier to access common actions for chat channels on desktop with a sidebar context menu. This works for both public and direct message channels. From here, you will be able to do the following actions: * Change the notification level for the channel, including muting or unmuting * Go directly to the channel settings * Star or unstar the channel * Leave the channel

Jan 5, 2026 (fc98ce9) Learn more →
Access common chat channel actions from the sidebar context menu

Security Fixes

CVE-2025-68660

AI Discover's continue conversation allows to impersonate user

Jan 28, 2026 View details →
CVE-2025-68659

DoS vulnerability in username change endpoint

Jan 28, 2026 View details →
CVE-2025-68666

Users archives leaked to users with moderation privileges

Jan 28, 2026 View details →
CVE-2025-69218

Moderators can access admin-only reports exposing private upload URLs

Jan 28, 2026 View details →
CVE-2025-69289

Insecure default configuration allows non-admin moderators to non-staff accounts via email change

Jan 28, 2026 View details →
CVE-2026-24742

Staff action logs expose sensitive information to moderators

Jan 28, 2026 View details →
CVE-2025-68479

Subscriptions are susceptible to takeover

Jan 28, 2026 View details →
CVE-2025-68662

FinalDestination hostname matching allows SSRF protection bypass

Jan 28, 2026 View details →
CVE-2026-23743

Permalinks to restricted resources leak resource slugs to unauthorized users

Jan 28, 2026 View details →
CVE-2026-21865

Topic conversion permission vulnerability for moderators

Jan 28, 2026 View details →
CVE-2025-68933

Non-admin moderators can exfiltrate private content via post ownership transfer

Jan 28, 2026 View details →
CVE-2025-68934

Denial of Service (DoS) Vulnerability in Drafts Creation Endpoint

Jan 28, 2026 View details →
CVE-2025-66488

Script execution in uploaded HTML/XML files on S3

Jan 28, 2026 View details →
CVE-2025-67723

Stored XSS via Katex in discourse-math plugin

Jan 28, 2026 View details →

Detailed Changes