CVE-2026-25552CWE-348

CVE-2026-25552

Low · published July 31, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
6.9
In the wild
Unconfirmed
What it is

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00173 · 6.9th percentile
Weakness
CWE-348 · Use of Less Trusted Source
Published
2026-07-31T23:17Z
References (2)
EPSS history
Timeline
  • 31 JUL 18:12Z
    Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
    cvelistv5