Description
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Published: 2026-10-05
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is a Regex Denial of Service that occurs when a crafted content import file is processed by Ghost. The bad input causes catastrophic backtracking in a regular expression, consuming excessive CPU and rendering the server unresponsive for users. The flaw requires the attacker to have Administrator privileges in the Ghost CMS.

Affected Systems

TryGhost Ghost versions from 4.0.0 through 6.67.0 are affected. The issue is fixed starting with version 6.67.0; later releases are not vulnerable. Admin users can trigger the exploit by uploading a malicious import file.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, but the lack of EPSS data and status outside KEV reduces the likelihood of widespread exploitation. Because the attack vector requires elevated privileges, the risk is primarily to organizations with compromised admin accounts or internal attackers. Patching remains the most reliable mitigation.

Generated by OpenCVE AI on October 5, 2026 at 20:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Ghost to version 6.67.0 or newer.
  • Restrict the content import feature to administrator accounts only if not already enforced.
  • Validate the size and format of import files before processing to avoid excessive CPU consumption.

Generated by OpenCVE AI on October 5, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
Title Ghost: Regular Expression Denial of Service in Content Import
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T18:58:26.224Z

Reserved: 2026-10-05T16:40:39.613Z

Link: CVE-2026-105646

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:19.373

Modified: 2026-10-05T19:17:19.373

Link: CVE-2026-105646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity