๐Ÿ” CVE Alert

CVE-2026-16270

UNKNOWN 0.0

ReDoS in Open Mercato

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.

CWE CWE-1333
Vendor open mercato
Product open mercato
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for open mercato open mercato

Be the first to know when new unknown vulnerabilities affecting open mercato open mercato are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Open Mercato / Open Mercato
0 < 0.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cert.pl: https://cert.pl/posts/2026/07/CVE-2026-16270 openmercato.com: https://www.openmercato.com/ github.com: https://github.com/open-mercato/open-mercato/pull/1996

Credits

Pawel Scibiorski