PatchSiren cyber security CVE debrief
CVE-2026-16270 Open Mercato CVE debrief
CVE-2026-16270 is a vulnerability in Open Mercato that allows an attacker with privileges to create a regex rule to add an unsafe regex to a field. When a proper string is provided, it can result in a DoS attack. The issue was fixed in version 0.6.4. Affected product deployments should be reviewed for exposure and patched or mitigated. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. Users with privileges to create regex rules should be cautious and ensure that their Open Mercato installations are reviewed and updated to prevent potential attacks.
- Vendor
- Open Mercato
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of Open Mercato, especially those with privileges to create regex rules, should be aware of this vulnerability and take steps to mitigate it. Operators, platform administrators, and security teams should review affected deployments and implement compensating controls if necessary. Security teams should prioritize patching or mitigating this vulnerability due to its potential impact on service availability.
Technical summary
Open Mercato does not validate regex rules, allowing an attacker with privileges to create a regex rule to add an unsafe regex to a field. When a proper string is provided, it can result in a DoS attack. The CVSS score for this vulnerability is 6.9, and the severity is MEDIUM. Defenders should focus on patching or mitigating this vulnerability. Open Mercato installations should be reviewed for exposure, and compensating controls should be implemented if necessary.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it can result in a DoS attack with a CVSS score of 6.9.
Recommended defensive actions
- Inventory and verify Open Mercato installations
- Restrict privileges for creating regex rules
- Implement compensating controls to detect and prevent DoS attacks
- Monitor for suspicious activity
- Apply the fix in version 0.6.4
- Review and update incident response plans
- Conduct vulnerability management reviews
Evidence notes
The CVE record was published on 2026-07-22T13:16:36.990Z and was last modified on 2026-07-22T20:54:47.023Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify Open Mercato installations and regex rule usage. The lack of validation on regex rules allows attackers to potentially cause a DoS attack, emphasizing the need for immediate review and mitigation.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T13:16:36.990Z and has not been modified since then. The NVD entry is currently Deferred.