| CVE ID | CVE-2026-16270 |
| Publication date | 22 July 2026 |
| Vendor | Open Mercato |
| Product | Open Mercato |
| Vulnerable versions | All before 0.6.4 |
| Vulnerability type (CWE) | Inefficient regular expression complexity (CWE-1333) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in Open Mercato software and participated in coordination of its disclosure.
The vulnerability CVE-2026-16270: Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to any field. When someone provides the proper string it can result in a DoS attack.
This issue was fixed in version 0.6.4.
Credits
We thank Pawel Scibiorski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.