Security research, CVE writeups, and insights from Kira.
Ghost maintained a hardened, DNS-rebinding-resistant HTTP library and used it everywhere — except webhook delivery, the one place where an admin directly controls the target URL.
One unauthenticated HTTP request. No login, no token, no credentials. Four independent weaknesses spread across the codebase, none dangerous alone, catastrophic together.