CVE-2026-16270
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
22/07/2026
Last modified:
22/07/2026
Description
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.<br />
<br />
<br />
This issue was fixed in version 0.6.4.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



