THREAT OPS › Threat News › [GHSA] GHSA-x5mm-wm4g-j5xv (medium) — Ghost: Server-Side Request Forgery Mitigation Issue
[GHSA] GHSA-x5mm-wm4g-j5xv (medium) — Ghost: Server-Side Request Forgery Mitigation Issue
GHSA-x5mm-wm4g-j5xv Severity: medium CVE: CVE-2026-70595
Ghost: Server-Side Request Forgery Mitigation Issue
### Impact
A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned.
### Vulnerable
Indicators of compromise
- CVE-2026-70595cve
- https://hub.docker.com/_/ghosturl
- https://docs.ghost.org/install/docker#updating-ghosturl
- https://docs.ghost.org/updateurl
- security@ghost.orgemail
Original source: https://github.com/advisories/GHSA-x5mm-wm4g-j5xv