CVE-2026-53944
published 2026-06-24CVE-2026-53944: Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the…
PriorityP433medium5.8CVSS 3.1
AVNACLPRNUINSCCNILAN
EPSS
0.33%
23.7th percentile
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address. This vulnerability is fixed in 6.21.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ghost | ghost | >= 6.0.9 < 6.21.1 | 6.21.1 |
| tryghost | ghost | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Ghost: Private IP filtering bypass to make server-side requests to internal services
ghsa·2026-08-04
CVE-2026-53944 [MEDIUM] CWE-184 Ghost: Private IP filtering bypass to make server-side requests to internal services
Ghost: Private IP filtering bypass to make server-side requests to internal services
### Impact
When making an external request, it is possible to bypass the IP filter that ensures the request isn't going to an internal service using an IPv6 literal which maps to a private IPv4 address.
### Vulnerable versions
This vulnerability is present in Ghost from v6.0.9 up to v6.21.0.
### Patches
v6.21.1 contains a fix for this issue.
### How to update
For self-hosters using Docker, find [Docker's official Ghost image here](https://hub.docker.com/_/ghost). Updating a Docker-based Ghost instance [is documented here](https://docs.ghost.org/install/docker#updating-ghost).
If your Ghost is a Ghost-CLI install see our documentation on [updating it to the latest version here](https://docs.ghost.o
VulDB
TryGhost up to 6.21.0 incomplete blacklist (GHSA-wvp2-4qqp-4h3r)
vuldb·2026-06-24·CVSS 5.8
CVE-2026-53944 [MEDIUM] TryGhost up to 6.21.0 incomplete blacklist (GHSA-wvp2-4qqp-4h3r)
A vulnerability was found in TryGhost Ghost up to 6.21.0 and classified as critical. Impacted is an unknown function. Executing a manipulation can lead to incomplete blacklist.
This vulnerability is registered as CVE-2026-53944. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published