CyberRota Analysis
AI-GeneratedOpen Mercato is vulnerable due to a lack of validation for regex rules, allowing privileged users to introduce unsafe regex patterns. This can lead to denial-of-service (DoS) attacks when properly crafted strings are processed. Organizations using Open Mercato should prioritize updating to version 0.6.4 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.