216.73.216.133

CVE-2026-24332

· Published 22/01/2026 08:16 · Modified 22/01/2026 08:16

Labels: CVE-2026-24332 2026-01-22CVE-2026-24332CWE-204[email protected]

Essential information

Published
22/01/2026 08:16
Modified
22/01/2026 08:16
Author
Creator
CVSS
4.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as "You will appear offline."

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
discord / discord cpe:2.3:a:discord:discord:*:*:*:*:*:*:*:*

References