Incomplete List of Disallowed Inputs in Ghost - #VU151946

 

Incomplete List of Disallowed Inputs in Ghost - #VU151946

Published: September 24, 2026


Vulnerability identifier: #VU151946
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to make limited HTTP requests to hosts on the Ghost server's internal network.

The vulnerability exists due to incomplete disallowed-input filtering in Ghost private IP filtering when processing IPv6 transition addresses. A remote attacker can submit a request that uses an IPv6 transition address to make limited HTTP requests to hosts on the Ghost server's internal network.

No response data is returned by successful requests, and exploitation is possible only on some network configurations.


Affected software

Ghost

Remediation

Install security update from vendor's website.

Ghost - update to 6.65.0

External References

Related Security Bulletins