Incomplete List of Disallowed Inputs in Ghost - #VU151946
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to make limited HTTP requests to hosts on the Ghost server's internal network.
The vulnerability exists due to incomplete disallowed-input filtering in Ghost private IP filtering when processing IPv6 transition addresses. A remote attacker can submit a request that uses an IPv6 transition address to make limited HTTP requests to hosts on the Ghost server's internal network.
No response data is returned by successful requests, and exploitation is possible only on some network configurations.