Open Mercato ReDoS Flaw Patched in 0.6.4
A ReDoS vulnerability in Open Mercato lets privileged users plant unsafe regex rules that can trigger denial of service, fixed in version 0.6.4.
CERT Polska coordinated disclosure of CVE-2026-16270, a vulnerability affecting Open Mercato software in which the application fails to validate regular expression rules submitted by users with rule-creation privileges. An attacker with such privileges could insert an unsafe (catastrophically backtracking) regex into any field; when a victim later supplies a specially crafted string matching that field, the resulting regex evaluation can consume excessive CPU resources, leading to a denial-of-service condition.
The issue requires an authenticated attacker with elevated privileges to create regex rules, limiting the attack surface to insiders or compromised privileged accounts rather than unauthenticated external actors. The vendor addressed the flaw in Open Mercato version 0.6.4. The report credits researcher Pawel Scibiorski for responsibly disclosing the vulnerability through CERT Polska's coordinated vulnerability disclosure process. No evidence of active exploitation is mentioned in the advisory.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-16270
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free