Open Mercato · Open Mercato · CVE-2026-16270
**Name of the Vulnerable Software and Affected Versions**
Open Mercato versions prior to 0.6.4
**Description**
Open Mercato fails to validate regular expression rules. An attacker with the necessary privileges to create these rules can insert an unsafe regex into a field. If a user provides a specific string that triggers this regex, it can lead to a Denial of Service (DoS) attack, which is a condition where the system becomes unavailable to its intended users.
**Recommendations**
Update to version 0.6.4.