THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x5mm-wm4g-j5xv (medium) — Ghost: Server-Side Request Forgery Mitigation Issue

[GHSA] GHSA-x5mm-wm4g-j5xv (medium) — Ghost: Server-Side Request Forgery Mitigation Issue

highgithub_advisoriesPublished 2026-08-05

GHSA-x5mm-wm4g-j5xv Severity: medium CVE: CVE-2026-70595

Ghost: Server-Side Request Forgery Mitigation Issue

### Impact

A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned.

### Vulnerable

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x5mm-wm4g-j5xv