THREAT OPS › Threat News › [GHSA] GHSA-ch52-px8q-f22j (medium) — Ghost: Server-side request forgery via DNS rebinding in external request handling
[GHSA] GHSA-ch52-px8q-f22j (medium) — Ghost: Server-side request forgery via DNS rebinding in external request handling
GHSA-ch52-px8q-f22j Severity: medium CVE: CVE-2026-53945
Ghost: Server-side request forgery via DNS rebinding in external request handling
### Impact
Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches.
### Vulnerable version
Indicators of compromise
- CVE-2026-53945cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- https://www.offgridsec.com/url
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-ch52-px8q-f22j