SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16270

MEDIUM · CVSS 6.9 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Open Mercato is vulnerable due to a lack of validation for regex rules, allowing privileged users to introduce unsafe regex patterns. This can lead to denial-of-service (DoS) attacks when properly crafted strings are processed. Organizations using Open Mercato should prioritize updating to version 0.6.4 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16270
Severity
MEDIUM
CVSS
6.9
EPSS
0.28%

Original NVD Description

Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.