Excessive CPU Usage Vulnerability in Ghost Node.js CMS
CVE-2026-105645
4.9MEDIUM
What is CVE-2026-105645?
Ghost, a widely used Node.js content management system, has a vulnerability that allows crafted requests to the external media inliner, potentially leading to excessive CPU usage. This can render the Ghost server unresponsive, significantly affecting web performance. Exploiting this issue necessitates Administrator access, highlighting the importance of securing administrative credentials. The vulnerability is addressed in version 6.67.0, and users are strongly advised to update their installations.
Affected Version(s)
Ghost >= 5.37.0, < 6.67.0
