CVE-2026-70595: Ghost: Server-Side Request Forgery Mitigation Issue
A validation issue allowed some functionality, such as Webmentions, to be abused by an unauthenticated user to make limited HTTP requests to hosts in the Ghost server’s internal network. A successful attack would not result in any response data being returned.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-70595 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →