CVE-2026-16270EPSS p39.6%
CVE-2026-16270CVE-2026-16270
Description
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.
This issue was fixed in version 0.6.4.
Scoring
| EPSS | 0.48% probability of exploitation · percentile 39.6% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-22 |