CVE-2026-53945
MEDIUMGhost: Server-side request forgery via DNS rebinding in external request handling
Title source: cnaDescription
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This vulnerability is fixed in 6.21.1.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/TryGhost/Ghost/security/advisories/GHSA-ch52-px8q-f22j
Scores
CVSS v3
4.0
EPSS
0.0014
EPSS Percentile
3.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-367
CWE-918
Status
published
Products (1)
TryGhost/Ghost
>= 6.0.9, < 6.21.1
Published
Jun 24, 2026
Tracked Since
Jun 25, 2026