What is CVE-2026-70595?
A validation flaw in Ghost CMS versions 6.26.0 to 6.54.1 allowed unauthenticated users to abuse Webmentions functionality and make limited HTTP requests to hosts on the Ghost server's internal network. This Server-Side Request Forgery (SSRF) vulnerability could lead to data exposure, and immediate upgrading to the patched version is recommended.
Azərbaycanca: Ghost CMS-in 6.26.0-6.54.1 versiyalarında autentifikasiya olunmamış istifadəçilərə Webmentions funksiyası vasitəsilə daxili şəbəkədəki hostlara məhdud HTTP sorğuları göndərməyə imkan verən yoxlama zəifliyi aşkarlanıb. Server-Side Request Forgery (SSRF) tipli bu hücum nəticəsində məlumat sızması baş verə bilər, dərhal yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Ghost CMS are affected by this vulnerability?
The CVE-2026-70595 vulnerability affects Ghost CMS versions 6.26.0 through 6.54.1.
Which functionality is exploited and what can this vulnerability lead to?
The vulnerability is exploited via the Webmentions functionality due to a validation flaw. This Server-Side Request Forgery (SSRF) attack can allow limited HTTP requests to internal network hosts and potentially lead to data exposure.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.