CVE-2026-105645
Received Received - Intake

Ghost CMS Denial of Service via Excessive CPU in External Media Inliner

Vulnerability report for CVE-2026-105645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TryGhost Ghost >= 5.37.0, < 6.67.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1333 The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Regular Expression Denial of Service (ReDoS) in the Ghost CMS. It occurs when a crafted request to the external media inliner causes excessive CPU usage, making the server unresponsive. The issue affects Ghost versions 5.37.0 through 6.65.0 and requires Administrator access to exploit.

Detection Guidance

Detecting this vulnerability requires checking Ghost server logs for excessive CPU usage during media inlining operations. Monitor for patterns where regex processing causes timeouts or server unresponsiveness. No specific commands are provided in the context, but you can use system monitoring tools like top, htop, or ps to observe CPU load spikes during Ghost operations.

Impact Analysis

This vulnerability can make the Ghost server unresponsive due to high CPU usage, disrupting service availability. It requires Administrator access to exploit, so unauthorized users cannot trigger it. Self-hosted users running affected versions should update to version 6.67.0 or later to mitigate the risk.

Compliance Impact

This vulnerability primarily impacts system availability due to excessive CPU usage, which could lead to service disruptions. While it does not directly expose or leak data, prolonged unavailability could interfere with logging, monitoring, or backup processes required by GDPR or HIPAA. However, the provided context does not specify direct compliance impacts beyond potential availability issues.

Mitigation Strategies

Immediately update Ghost to version 6.67.0 or later to patch the vulnerability. If updating is not possible, restrict Administrator access to the Ghost server to prevent exploitation. Monitor server performance and disable the external media inliner if excessive CPU usage is detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105645. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart