Input validation error in Ghost - CVE-2026-70595
Published: July 30, 2026 / Updated: August 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to make limited HTTP requests to hosts in the server's internal network.
The vulnerability exists due to improper input validation in Webmentions functionality when handling user-supplied URLs. A remote attacker can submit a specially crafted request to make limited HTTP requests to hosts in the server's internal network.
No response data is returned to the requester.