GHSA-62q6-4hv4-vjrw
CRITICALCVE-2026-53943When Ghost is behind a shared caching layer that results in cached content being shared between different visitors (e.g., Fastly, Cloudflare, nginx proxycache, and others), an unauthenticated user could send an x-ghost-preview header that altered the rendered frontend response. In affected cache configurations, that response could be stored and served to subsequent visitors requesting the same pag
- Affected
- >= 4.0.0, <= 6.36.0
- Fixed in
- 6.37.0
- Weakness
- CWE-524
- Published
- 2026-07-01
- Source
- github