PT-2026-105101 · Bitnami · Ghost

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy add x forwarded for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-GHOST-2026-25552

Affected Products

Ghost