Open Mercato does not validate regex rules. An attacker...
Moderate severity
Unreviewed
Published
Jul 22, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jul 22, 2026
Published to the GitHub Advisory Database
Jul 22, 2026
Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack.
This issue was fixed in version 0.6.4.
References