CVE-2026-53945

Source
https://cve.org/CVERecord?id=CVE-2026-53945
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53945.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-53945
Aliases
  • GHSA-ch52-px8q-f22j
Published
2026-06-24T18:09:34.909Z
Modified
2026-06-26T03:55:24.861527819Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N CVSS Calculator
Summary
Ghost: Server-side request forgery via DNS rebinding in external request handling
Details

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghost server into reaching hosts on internal networks through features that issue external fetches. This vulnerability is fixed in 6.21.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53945.json",
    "cwe_ids": [
        "CWE-367",
        "CWE-918"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/tryghost/ghost

Affected ranges

Type
GIT
Repo
https://github.com/tryghost/ghost
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "6.0.9"
        },
        {
            "fixed": "6.21.1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-53945.json"