THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-ch52-px8q-f22j (medium) — Ghost: Server-side request forgery via DNS rebinding in external request handling

[GHSA] GHSA-ch52-px8q-f22j (medium) — Ghost: Server-side request forgery via DNS rebinding in external request handling

highgithub_advisoriesPublished 2026-08-04

GHSA-ch52-px8q-f22j Severity: medium CVE: CVE-2026-53945

Ghost: Server-side request forgery via DNS rebinding in external request handling

### Impact

Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches.

### Vulnerable version

Indicators of compromise

Original source: https://github.com/advisories/GHSA-ch52-px8q-f22j