Skip to main content
Vulnerability Database/CVE-2026-105646

CVE-2026-105646: Ghost CMS Denial of Service Vulnerability

CVE-2026-105646 is a denial of service vulnerability in Ghost CMS that allows administrators to cause excessive CPU usage through crafted import files. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-105646 Overview

Ghost, a Node.js content management system, contains a Regular Expression Denial of Service (ReDoS) vulnerability affecting versions 4.0.0 through 6.66.x. A crafted content import file can cause excessive CPU consumption, rendering the Ghost server unresponsive. Exploitation requires Administrator access to the Ghost instance, which limits the attack to authenticated privileged users. The issue is tracked under [CWE-1333: Inefficient Regular Expression Complexity] and was addressed in Ghost 6.67.0 through improved regex escaping in the import file handlers. The GitHub Security Advisory GHSA-fwh9-qg68-vxp4 documents the fix.

Critical Impact

An authenticated administrator can upload a malicious content import file that exhausts server CPU, causing a sustained denial of service for all Ghost users.

Affected Products

  • Ghost (Node.js CMS) versions 4.0.0 through 6.66.x
  • Ghost self-hosted deployments relying on the content importer
  • Ghost multi-tenant instances where administrator import is permitted

Discovery Timeline

  • 2026-10-05 - CVE-2026-105646 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-105646

Vulnerability Analysis

The flaw resides in Ghost's content import handlers, specifically in ghost/core/core/server/data/importer/handlers/image.js and importer-content-file-handler.js. Both files construct regular expressions by concatenating a user-influenced baseDir value and storage prefix segments directly into new RegExp(...) calls. When a crafted import archive supplies directory names containing regex metacharacters, the resulting pattern becomes pathological and triggers catastrophic backtracking.

Because Node.js executes regular expressions synchronously on the main event loop, a single abusive import pins CPU to 100% and blocks all incoming requests. The server remains unresponsive until the operation completes or the process is restarted. Exploitation requires an Administrator session, so the attacker must already hold privileged credentials or compromise an administrator account.

Root Cause

The root cause is missing input sanitization when building dynamic regular expressions. User-controlled strings are inserted into regex source without escaping metacharacters such as (, ), *, +, ?, and |. This classifies as [CWE-1333] Inefficient Regular Expression Complexity.

Attack Vector

An authenticated administrator uploads a specially crafted content export archive through Ghost's import feature. The archive contains file or directory names engineered to produce a backtracking-heavy regex when combined with the storage prefix logic.

javascript
// Patch excerpt from ghost/core/core/server/data/importer/handlers/image.js
 loadFile: function (files, baseDir) {
   const store = adapterManager.getAdapter('storage:images');
-  const baseDirRegex = baseDir ? new RegExp('^' + baseDir + '/') : new RegExp('');
+  const baseDirRegex = baseDir ? new RegExp('^' + _.escapeRegExp(baseDir) + '/') : new RegExp('');

   const imageFolderRegexes = _.map(store.staticFileURLPrefix.split('/'), function (dir) {
-    return new RegExp('^' + dir + '/');
+    return new RegExp('^' + _.escapeRegExp(dir) + '/');
   });

Source: GitHub Commit 88ae6d6. The fix wraps every user-influenced value with Lodash _.escapeRegExp() before passing it to new RegExp().

Detection Methods for CVE-2026-105646

Indicators of Compromise

  • Sustained Node.js process CPU utilization at or near 100% following an import operation
  • Ghost API and admin UI becoming unresponsive while import jobs are queued or active
  • Access logs showing POST /ghost/api/admin/db/ or import endpoint calls preceding the slowdown
  • Import archive uploads containing directory or file names with unusual regex metacharacter sequences

Detection Strategies

  • Monitor Ghost application logs for long-running import jobs that never complete or exceed baseline duration
  • Alert on node process CPU exhaustion correlated with authenticated administrator sessions
  • Inspect uploaded import ZIP archives for entries whose names contain repeated grouping or alternation characters

Monitoring Recommendations

  • Enable audit logging for all administrator authentication events and import endpoint invocations
  • Instrument Ghost with event-loop lag metrics to catch synchronous blocking from pathological regexes
  • Review administrator account activity for unexpected imports, particularly from newly created or dormant accounts

How to Mitigate CVE-2026-105646

Immediate Actions Required

  • Upgrade Ghost to version 6.67.0 or later, which contains the regex escaping fix
  • Audit all accounts holding the Administrator role and remove unused or stale privileged accounts
  • Enforce multi-factor authentication on administrator logins to reduce credential compromise risk
  • Restrict administrative panel access to known IP ranges or VPN sessions where feasible

Patch Information

The fix is included in Ghost v6.67.0 and originates from pull request #31058. The patch introduces _.escapeRegExp() around baseDir and storage prefix values in both image.js and importer-content-file-handler.js. Refer to the GitHub Security Advisory GHSA-fwh9-qg68-vxp4 and the GitHub Pull Request #31058 for complete details.

Workarounds

  • Temporarily disable the content import feature or restrict its use to a controlled maintenance window
  • Review and sanitize import archives offline before uploading, rejecting files with regex metacharacters in paths
  • Place Ghost behind a reverse proxy with request timeouts to force termination of hung import operations
bash
# Verify installed Ghost version and upgrade using Ghost-CLI
ghost version
ghost update --v 6.67.0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.