PT-2026-94344 · Vendure · Vendure

·

CVE-2026-63460

·

Published

2026-09-17

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vendure versions prior to 3.6.5
Description An unauthenticated Regular Expression Denial of Service (ReDoS) exists in the public Shop GraphQL API. The issue occurs when the StringOperators.regex filter is used, as the raw pattern is passed to a synchronous SQLite user-defined function (UDF) that executes within the Node.js event loop. An attacker can provide a catastrophically backtracking pattern—such as one containing nested quantifiers—to block the event loop, making the storefront and admin API unavailable. This specifically affects deployments using the better-sqlite3 or sqljs database drivers. The ShopProductsResolver.products resolver is publicly accessible, allowing this attack to be triggered without authentication. PostgreSQL, MySQL, and MariaDB deployments are not affected as they do not execute this regular expression in the Node.js event loop.
Recommendations Update to version 3.6.5. As a temporary mitigation, restrict access to the ShopProductsResolver.products resolver to authenticated users only if anonymous browsing is not required.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63460
GHSA-JGM3-QMP2-C4P7

Affected Products

Vendure