Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ghost
Ghost ghost |
|
| Vendors & Products |
Ghost
Ghost ghost |
Wed, 24 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1. | |
| Title | Ghost: Private IP filtering bypass to make server-side requests to internal services | |
| Weaknesses | CWE-184 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-24T18:10:30.985Z
Updated: 2026-06-24T18:50:17.772Z
Reserved: 2026-06-11T15:50:01.280Z
Link: CVE-2026-53944
Updated: 2026-06-24T18:50:14.901Z
No data.
No data.