Description
Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Published: 2026-10-05
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Ghost, a Node.js content management system, is vulnerable to a regular expression denial of service through its external media inliner. A crafted request can cause the server to consume excessive CPU, rendering the web application unresponsive. The flaw is classified as CWE‑1333, indicating that a single client can trigger a computationally expensive regular expression that exhausts system resources.

Affected Systems

The vulnerability affects Ghost versions from 5.37.0 through 6.66.x inclusive. All installations running any of these releases must be checked. Exploitation requires an administrator account to send the specially crafted request, so only users with elevated privileges can activate the denial of service.

Risk and Exploitability

The CVSS score is 4.9, placing the issue in the medium severity range. EPSS data is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploitation yet. Nevertheless, because the attack requires admin access, an attacker who acquires such privileges can force the Ghost server into a state of resource exhaustion and loss of availability.

Generated by OpenCVE AI on October 5, 2026 at 20:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Ghost 6.67.0 update or later to remove the vulnerable regular expression.
  • Restrict or disable the external media inliner route for users who do not need it, limiting exposure to privileged accounts.
  • After updating, monitor server CPU usage and consider implementing rate limiting on the inliner endpoint to prevent future denial of service attempts.

Generated by OpenCVE AI on October 5, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From 5.37.0 until 6.67.0, a crafted request to the external media inliner could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Title Ghost: Regular Expression Denial of Service in External Media Inliner
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:08:46.517Z

Reserved: 2026-10-05T16:40:39.612Z

Link: CVE-2026-105645

cve-icon Vulnrichment

Updated: 2026-10-05T19:08:42.579Z

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:19.223

Modified: 2026-10-05T20:17:13.013

Link: CVE-2026-105645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity