PatchSiren cyber security CVE debrief
CVE-2026-105645 TryGhost CVE debrief
A crafted request to the external media inliner in Ghost could cause excessive CPU usage, making the server unresponsive. This requires Administrator access and affects Ghost versions from 5.37.0 up to 6.65.0. The issue is fixed in version 6.67.0. Defenders managing Ghost installations should assess exposure and prioritize updates, especially for self-hosted instances using Docker or Ghost-CLI. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context.
- Vendor
- TryGhost
- Product
- ghost
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders managing Ghost installations, especially self-hosted instances using Docker or Ghost-CLI, should assess exposure and prioritize updates. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context. Defenders should verify the affected versions and update to version 6.67.0 or later.
Why it matters
Defenders should prioritize updating Ghost instances to version 6.67.0 or later due to a potential denial of service vulnerability. Self-hosted installations using Docker or Ghost-CLI require immediate attention.
- Potential for excessive CPU usage leading to server unresponsiveness
- Requires Administrator access for exploitation
- Fixed in version 6.67.0, with specific update instructions for Docker and Ghost-CLI installations
Technical summary
A crafted request to the external media inliner in Ghost could cause excessive CPU usage, making the server unresponsive. This requires Administrator access and affects Ghost versions from 5.37.0 up to 6.65.0. The issue is fixed in version 6.67.0. Defenders managing Ghost installations, especially self-hosted instances using Docker or Ghost-CLI, should assess exposure and prioritize updates. The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context.
Defensive priority
Defenders should prioritize updating Ghost instances to version 6.67.0 or later, especially for self-hosted installations using Docker or Ghost-CLI.
Recommended defensive actions
- Update Ghost instances to version 6.67.0 or later
- Review and apply the provided patches for Docker-based and Ghost-CLI installations
- Monitor for potential excessive CPU usage in Ghost servers
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability details are based on the source item from osv_dev and references from the Ghost project. The CVE Program and NVD provide additional context. Defenders should verify the affected versions and update to version 6.67.0 or later. Self-hosted installations using Docker or Ghost-CLI require immediate attention. The issue is fixed in version 6.67.0, with specific update instructions for Docker and Ghost-CLI installations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105645 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105645
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105645 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105645
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Ghost: Regular Expression Denial of Service in External Media Inliner
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-9m4w-fmjw-fvjq.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/security/advisories/GHSA-9m4w-fmjw-fvjq
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/issues/31058
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/pull/31058
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/commit/88ae6d6d56f8a239cb38a8c89de02f034f50e2ce
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/TryGhost/Ghost/releases/tag/v6.66.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.