CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS
Vulnerability ID: CVE-2026-105645
CVSS Score: 4.9
Published: 2026-10-07
CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.
TL;DR
An authenticated administrator can cause a permanent Denial of Service (DoS) of the Ghost CMS server by uploading a crafted ZIP containing recursive/nested directory patterns or triggering malicious wildcard domain matching in the external media inliner, freezing the single-threaded Node.js event loop.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-1333
- Attack Vector: Network
- CVSS v3.1 Score: 4.9 (Medium)
- EPSS Score: 0.00327 (Percentile: 23.71%)
- Impact: Denial of Service (Availability)
- Exploit Status: Proof of Concept (PoC)
- KEV Status: Not Listed
Affected Systems
- TryGhost/Ghost CMS deployment environments
-
Ghost: >= 5.37.0, < 6.67.0 (Fixed in:
6.67.0)
Code Analysis
Commit: 88ae6d6
Fix ReDoS vulnerabilities in Ghost content import handlers and external media inliner matching logic.
Exploit Details
- GitHub: Regression test suite proving catastrophic backtracking paths in importer-content-file-handler and external-media-inliner.
Mitigation Strategies
- Upgrade Ghost instances immediately to version 6.67.0 or higher.
- Sanitize file import variables by escaping dynamic parameters inside RegExp constructors using safe escaping utility functions.
- Isolate computational or regular expression matching mechanisms for dynamic patterns using the node:vm module with a defined timeout.
Remediation Steps:
- Navigate to the terminal hosting your Ghost application.
- Execute the update script:
ghost updateto acquire version 6.67.0 or higher. - Verify successful container or service restart via monitoring utilities.
- Examine logs for any instances of MEDIA_INLINER_PATTERN_TIMEOUT errors that indicate attempted or blocked ReDoS attempts.
References
- GitHub Security Advisory GHSA-9m4w-fmjw-fvjq
- Official Patch Commit
- Ghost Release Tag v6.66.0
- Vulnerability Tracking Issue
Read the full report for CVE-2026-105645 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)