PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105645 TryGhost CVE debrief

A crafted request to the external media inliner in Ghost could cause excessive CPU usage, making the server unresponsive. This requires Administrator access and affects Ghost versions from 5.37.0 up to 6.65.0. The issue is fixed in version 6.67.0. Defenders managing Ghost installations should assess exposure and prioritize updates, especially for self-hosted instances using Docker or Ghost-CLI. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context.

Vendor
TryGhost
Product
ghost
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders managing Ghost installations, especially self-hosted instances using Docker or Ghost-CLI, should assess exposure and prioritize updates. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context. Defenders should verify the affected versions and update to version 6.67.0 or later.

Why it matters

Defenders should prioritize updating Ghost instances to version 6.67.0 or later due to a potential denial of service vulnerability. Self-hosted installations using Docker or Ghost-CLI require immediate attention.

  • Potential for excessive CPU usage leading to server unresponsiveness
  • Requires Administrator access for exploitation
  • Fixed in version 6.67.0, with specific update instructions for Docker and Ghost-CLI installations

Technical summary

A crafted request to the external media inliner in Ghost could cause excessive CPU usage, making the server unresponsive. This requires Administrator access and affects Ghost versions from 5.37.0 up to 6.65.0. The issue is fixed in version 6.67.0. Defenders managing Ghost installations, especially self-hosted instances using Docker or Ghost-CLI, should assess exposure and prioritize updates. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context.

Defensive priority

Defenders should prioritize updating Ghost instances to version 6.67.0 or later, especially for self-hosted installations using Docker or Ghost-CLI.

Recommended defensive actions

  • Update Ghost instances to version 6.67.0 or later
  • Review and apply the provided patches for Docker-based and Ghost-CLI installations
  • Monitor for potential excessive CPU usage in Ghost servers
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context. Defenders should verify the affected versions and update to version 6.67.0 or later. Self-hosted installations using Docker or Ghost-CLI require immediate attention. The issue is fixed in version 6.67.0, with specific update instructions for Docker and Ghost-CLI installations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105645 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105645

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105645 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105645

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Ghost: Regular Expression Denial of Service in External Media Inliner

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-9m4w-fmjw-fvjq.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-9m4w-fmjw-fvjq

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/issues/31058

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/pull/31058

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/commit/88ae6d6d56f8a239cb38a8c89de02f034f50e2ce

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/TryGhost/Ghost/releases/tag/v6.66.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.