CVE-2026-105646
MEDIUM
4,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Ghost is a Node.js content management system. From 4.0.0 until 6.67.0, a crafted content import file could cause excessive CPU usage, making the Ghost server unresponsive. Exploiting this requires Administrator access. This issue is fixed in version 6.67.0.
1333
Inefficient Regular Expression Complexity
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Cpu)
Applicable Platforms
All platforms may be affected
https://github.com/TryGhost/Ghost/commit/88ae6d6d56f8a239cb38a8c89de02f034f50e2…
https://github.com/TryGhost/Ghost/pull/31058
https://github.com/TryGhost/Ghost/releases/tag/v6.66.0
https://github.com/TryGhost/Ghost/security/advisories/GHSA-fwh9-qg68-vxp4