CVE-2026-16270: Open Mercato
Medium severity, CVSS 6.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.
Affected products
- Open Mercato Open Mercato: before 0.6.4 (fixed in 0.6.4)
Published 2026-07-22. Last modified 2026-07-22.