# CVE-2021-41163 false positive

**URL:** <https://meta.discourse.org/t/cve-2021-41163-false-positive/392820>\
**Category:** Support\
**Created:** [January 6, 2026, 8:15pm UTC](https://meta.discourse.org/t/cve-2021-41163-false-positive/392820 "2026-01-06T20:15:19Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![rbos](https://avatars.discourse-cdn.com/v4/letter/r/b3f665/32.png) [@rbos](https://meta.discourse.org/u/rbos)\
**Post date:** [January 6, 2026, 8:15pm UTC](https://meta.discourse.org/t/cve-2021-41163-false-positive/392820/1 "2026-01-06T20:15:19Z")

</div>

Hi,

I’m getting messages from our central IT complaining that our Discourse instance is triggering a security warning on CVE-2021-41163, which regards the /webhooks/aws endpoint.

I’ve told them that we’ve kept the software up to date since 2021 (we do a “launcher app rebuild” every month automatically) but their scanner is still flagging it as a problem. It’s convinced we’re running a version before 2.7.8 (2021), but we’re on 2026.01.0-latest. So I’m pretty sure their scanner is just mis-parsing the version string, or detecting the existence of the endpoint and complaining about that.

I’m 99% sure it’s not a problem, but I need to convince _them_ of that.

Is there a clean way of disabling the AWS webhooks endpoint without having to tweak discourse.conf? That would probably mollify them.

Of course there’s always that 1% possibility that we’re NOT patched, in which case, I’d be happy to have some way of testing that. I did some grepping through `git log` but I don’t see a specific reference to that CVE.

Advice?

---

_[View the full topic](https://meta.discourse.org/t/cve-2021-41163-false-positive/392820)._
