Threats Tagged 'cve-2026-70595'
View all threats tagged with 'cve-2026-70595'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-70595'
Click on any threat for detailed analysis and mitigation recommendations
Ghost: Server-Side Request Forgery Mitigation Issue (CVE-2026-70595)CVE-2026-70595 0 ### Impact A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server's internal network. A successful attack would not result in any response data being returned. ### Vulnerable versions This vulnerability is present in Ghost from v6.26.0 up to v6.54.0. ### Patches v6.54.1 contains a fix for this issue. ### How to update For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost). If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.org/update). ### References Ghost thanks Hwang Seyeon for disclosing this vulnerability responsibly. ### For more information If you have any questions or comments about this advisory, email Ghost at [[email protected]](mailto:[email protected]). Join the discussion | GCVE Database | 08/05/2026, 14:37:14 UTC Added: 08/05/2026, 15:30:52 UTC |
Showing 1 to 1 of 1 result