Article
Cyber News / Article / Vulnerability in Open Mercato software

CE
CERT Polska-2026-07-22
Vulnerability in Open Mercato software
CERT Polska has received a report about vulnerability in Open Mercato software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-16270: Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to any field. When someone provides the proper string it can result in a DoS attack.
This issue was fixed in version 0.6.4.
We thank Pawel Scibiorski for the responsible vulnerability report.
