DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105645: CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

Vulnerability ID: CVE-2026-105645
CVSS Score: 4.9
Published: 2026-10-07

CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.

TL;DR

An authenticated administrator can cause a permanent Denial of Service (DoS) of the Ghost CMS server by uploading a crafted ZIP containing recursive/nested directory patterns or triggering malicious wildcard domain matching in the external media inliner, freezing the single-threaded Node.js event loop.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-1333
  • Attack Vector: Network
  • CVSS v3.1 Score: 4.9 (Medium)
  • EPSS Score: 0.00327 (Percentile: 23.71%)
  • Impact: Denial of Service (Availability)
  • Exploit Status: Proof of Concept (PoC)
  • KEV Status: Not Listed

Affected Systems

  • TryGhost/Ghost CMS deployment environments
  • Ghost: >= 5.37.0, < 6.67.0 (Fixed in: 6.67.0)

Code Analysis

Commit: 88ae6d6

Fix ReDoS vulnerabilities in Ghost content import handlers and external media inliner matching logic.

Exploit Details

  • GitHub: Regression test suite proving catastrophic backtracking paths in importer-content-file-handler and external-media-inliner.

Mitigation Strategies

  • Upgrade Ghost instances immediately to version 6.67.0 or higher.
  • Sanitize file import variables by escaping dynamic parameters inside RegExp constructors using safe escaping utility functions.
  • Isolate computational or regular expression matching mechanisms for dynamic patterns using the node:vm module with a defined timeout.

Remediation Steps:

  1. Navigate to the terminal hosting your Ghost application.
  2. Execute the update script: ghost update to acquire version 6.67.0 or higher.
  3. Verify successful container or service restart via monitoring utilities.
  4. Examine logs for any instances of MEDIA_INLINER_PATTERN_TIMEOUT errors that indicate attempted or blocked ReDoS attempts.

References


Read the full report for CVE-2026-105645 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)