PatchSiren cyber security CVE debrief
CVE-2026-16270 Open Mercato CVE debrief
CVE-2026-16270 is a vulnerability in Open Mercato that allows an attacker with privileges to create a regex rule to add an unsafe regex to a field. When a proper string is provided, it can result in a DoS attack. The issue was fixed in version 0.6.4. Affected product deployments should be reviewed for exposure and patched or mitigated. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. Users with privileges to create regex rules should be cautious and ensure that their Open Mercato installations are reviewed and updated to prevent potential attacks.
- Vendor
- Open Mercato
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Users of Open Mercato, especially those with privileges to create regex rules, should be aware of this vulnerability and take steps to mitigate it. Operators, platform administrators, and security teams should review affected deployments and implement compensating controls if necessary. Security teams should prioritize patching or mitigating this vulnerability due to its potential impact on service availability.
Technical summary
Open Mercato does not validate regex rules, allowing an attacker with privileges to create a regex rule to add an unsafe regex to a field. When a proper string is provided, it can result in a DoS attack. The CVSS score for this vulnerability is 6.9, and the severity is MEDIUM. Defenders should focus on patching or mitigating this vulnerability. Open Mercato installations should be reviewed for exposure, and compensating controls should be implemented if necessary.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it can result in a DoS attack with a CVSS score of 6.9.
Recommended defensive actions
- Inventory and verify Open Mercato installations
- Restrict privileges for creating regex rules
- Implement compensating controls to detect and prevent DoS attacks
- Monitor for suspicious activity
- Apply the fix in version 0.6.4
- Review and update incident response plans
- Conduct vulnerability management reviews
Evidence notes
The CVE record was published on 2026-07-22T13:16:36.990Z and was last modified on 2026-07-22T20:54:47.023Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify Open Mercato installations and regex rule usage. The lack of validation on regex rules allows attackers to potentially cause a DoS attack, emphasizing the need for immediate review and mitigation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16270 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16270
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16270 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16270
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cert.pl/posts/2026/07/CVE-2026-16270
-
Source reference
Unverified legacy reference
URL: https://github.com/open-mercato/open-mercato/pull/1996
-
Source reference
Unverified legacy reference
URL: https://www.openmercato.com/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.