# Open Mercato ReDoS Flaw Patched in 0.6.4

Published: 2026-07-22 · Severity: low
Canonical: https://vorant.io/reports/55642ba9-e45c-56d9-839f-7fa5c4b89c0f/open-mercato-redos-flaw-patched-in-0-6-4

> A ReDoS vulnerability in Open Mercato lets privileged users plant unsafe regex rules that can trigger denial of service, fixed in version 0.6.4.

CERT Polska coordinated disclosure of CVE-2026-16270, a vulnerability affecting Open Mercato software in which the application fails to validate regular expression rules submitted by users with rule-creation privileges. An attacker with such privileges could insert an unsafe (catastrophically backtracking) regex into any field; when a victim later supplies a specially crafted string matching that field, the resulting regex evaluation can consume excessive CPU resources, leading to a denial-of-service condition.

The issue requires an authenticated attacker with elevated privileges to create regex rules, limiting the attack surface to insiders or compromised privileged accounts rather than unauthenticated external actors. The vendor addressed the flaw in Open Mercato version 0.6.4. The report credits researcher Pawel Scibiorski for responsibly disclosing the vulnerability through CERT Polska's coordinated vulnerability disclosure process. No evidence of active exploitation is mentioned in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-16270

Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-16270

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/55642ba9-e45c-56d9-839f-7fa5c4b89c0f/open-mercato-redos-flaw-patched-in-0-6-4.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
