CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-25552

lowCVSS 3.7covered by 1 sourcefirst seen 2026-07-31
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.

⚡ Watch CVE-2026-25552

Get an email if CVE-2026-25552 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-25552

CVE.org record

Embed the live status

CVE-2026-25552 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-25552 status](https://www.csirts.com/badge/CVE-2026-25552)](https://www.csirts.com/cve/CVE-2026-25552)