# 2.8.9: Security Release

**URL:** https://meta.discourse.org/t/2-8-9-security-release/239869
**Category:** Announcements
**Tags:** release-notes
**Created:** [September 29, 2022, 7:02pm UTC](https://meta.discourse.org/t/2-8-9-security-release/239869 "2022-09-29T19:02:04Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [September 29, 2022, 7:02pm UTC](https://meta.discourse.org/t/2-8-9-security-release/239869/1 "2022-09-29T19:02:04Z")

</div>

## Discourse 2.8.9 Stable Release

Discourse strongly recommends that all sites follow the default tests-passed branch of Discourse. The “stable” branch is more focused on _lack of change_ than _lack of bugs_ - all releases, including those on tests-passed and beta are production ready.

### Changes

#### Security:

- Limit user profile field length ([CVE-2022-39226](https://github.com/discourse/discourse/security/advisories/GHSA-jw3q-xg5g-qjrw))
- Moderator shouldn’t be able to import a theme via API ([CVE-2022-36068](https://github.com/discourse/discourse/security/advisories/GHSA-6crr-3662-263q))
- Prevent arbitrary file write when decompressing files ([CVE-2022-36066](https://github.com/discourse/discourse/security/advisories/GHSA-grvh-qcpg-hfmv))
