CVE-2026-105646: Ghost: Regular Expression Denial of Service in Content Import
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ghostto a version that resolves this vulnerability.Fixed in 6.67.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Administrator access to Ghost and must be able to submit a crafted content import file. It is not exploitable by an unauthenticated remote user based on the provided information.
What is the operational impact of successful exploitation?
Processing the crafted import can consume excessive CPU resources and make the Ghost server unresponsive. The provided vector indicates an availability impact only, with no stated confidentiality or integrity impact.
Which deployments need to be remediated?
Ghost versions from 4.0.0 through 6.67.0 are identified as affected. Update to version 6.67.0, which contains the fix.