CVE-2026-105645: Ghost: Regular Expression Denial of Service in External Media Inliner
Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.67.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires Administrator access to Ghost. Unauthenticated users and lower-privileged accounts are not identified as able to trigger it by the available information.
Which deployments are affected?
Ghost versions from 5.37.0 through versions before 6.67.0 are affected. The issue is fixed in Ghost 6.67.0.
What is the impact of successful exploitation?
A crafted request to the external media inliner can consume excessive CPU resources and make the Ghost server unresponsive. The reported impact is availability only; no confidentiality or integrity impact is listed.