Summary
Ghost: Private IP filtering bypass to make server-side requests to internal services
Advisory details
Impact
When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.
Vulnerable versions
This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.
Patches
v6.21.1 contains a fix for this issue.
How to update
For self-hosters using Docker, find Docker's official Ghost image here. Updating a Docker-based Ghost instance is documented here.
If your Ghost is a Ghost-CLI install see our documentation on updating it to the latest version here.
References
Ghost thanks l3tchupkt for disclosing this vulnerability responsibly.
For more information
If you have any questions or comments about this advisory, email us at security@ghost.org.
References
- https://github.com/advisories/GHSA-wvp2-4qqp-4h3r
- https://github.com/TryGhost/Ghost/security/advisories/GHSA-wvp2-4qqp-4h3r
- https://nvd.nist.gov/vuln/detail/CVE-2026-53944
- https://github.com/TryGhost/Ghost/pull/26749
- https://github.com/TryGhost/Ghost/commit/9b7f2212970fade08ecbec543b405190471e38d4
- https://github.com/TryGhost/Ghost/releases/tag/v6.21.1
Related vulnerabilities
All Supply chain →- HIGHCVE-2026-52776
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
- CRITICALCVE-2026-75856
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
- CRITICALCVE-2026-71428
unstructured: Server-Side Request Forgery in the URL-based partitioning
- MEDIUMCVE-2026-68921
DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
- HIGHCVE-2026-62676
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
- HIGHCVE-2026-65842
Plate: SSRF with response disclosure in DOCX image embedding