CVE-2026-105647
Received Received - Intake

Ghost CMS Internal Network Request Validation Bypass

Vulnerability report for CVE-2026-105647, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 6.54.1 until 6.65.0, a validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. This issue is fixed in version 6.65.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 6.54.1, < 6.65.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105647 is a Server-Side Request Forgery (SSRF) vulnerability in Ghost CMS affecting versions 6.54.1 through 6.64.0. It allows unauthenticated users to exploit Webmentions to make limited HTTP requests to internal network hosts without receiving response data. The issue stems from improper URL validation and a TOCTOU race condition.

Detection Guidance

Detecting this SSRF vulnerability in Ghost CMS requires checking for unauthorized internal network requests. Monitor logs for Webmention-related HTTP requests to internal IPs or unusual favicon lookups. Use network traffic analysis tools like tcpdump or Wireshark to inspect outbound requests from the Ghost server. Check for requests to private IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Ensure Ghost is updated to version 6.65.0 or later.

Impact Analysis

An attacker could use this to probe internal network services, potentially discovering vulnerable hosts or services. While no data is returned, the attack could be used to map internal infrastructure or trigger unintended actions if combined with other vulnerabilities.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it does not involve unauthorized data access, disclosure, or processing of personal data. The SSRF flaw allows limited internal network requests without response data, which does not violate typical data protection requirements under these regulations.

Mitigation Strategies

Update Ghost CMS to version 6.65.0 or later to patch the SSRF vulnerability. For Docker-based installations, pull the latest image and redeploy. For Ghost-CLI installations, run 'ghost update' to upgrade.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105647. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart