Incomplete List of Disallowed Inputs in Ghost - CVE-2026-53944
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to make server-side requests to internal services.
The vulnerability exists due to incomplete list of disallowed inputs in the external request IP filter when processing an IPv6 literal that maps to a private IPv4 address. A remote attacker can supply a crafted IPv6 literal to make server-side requests to internal services.