What is CVE-2026-16270?
CVE-2026-16270 is a vulnerability in Open Mercato where regex rules are not validated. This allows a privileged attacker to inject an unsafe regex, potentially leading to a Denial-of-Service (DoS) attack when a specifically crafted string is provided. The issue has been fixed in version 0.6.4.
Azərbaycanca: CVE-2026-16270 boşluğu Open Mercato platformasında regex qaydalarının düzgün yoxlanılmaması ilə bağlıdır. Bu, imtiyazlı istifadəçiyə təhlükəli regex yerləşdirməyə imkan verir və xüsusi sətir daxil edildikdə xidmət əleyhinə DoS hücumuna səbəb ola bilər. Problem 0.6.4 versiyasında aradan qaldırılıb.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What type of attack can CVE-2026-16270 lead to in the Open Mercato platform?
This vulnerability allows a privileged attacker to inject an unsafe regex, potentially leading to a Denial-of-Service (DoS) attack when a specifically crafted string is provided.
In which version has the CVE-2026-16270 issue been fixed?
The issue has been fixed in Open Mercato version 0.6.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.