Impact
Open Mercato does not validate the syntax of user‑defined regular expressions. An attacker who can create such a rule can insert an unsafe pattern that triggers catastrophic backtracking. When an input string matching the pattern is processed, the system may freeze or consume excessive CPU, resulting in a denial‑of‑service condition for the application and its users.
Affected Systems
Vendors: Open Mercato. Product: Open Mercato. Versions before 0.6.4 are vulnerable. The issue was fixed in 0.6.4, so any release lower than that should be considered affected.
Risk and Exploitability
CVSS score of 6.9 indicates moderate severity. EPSS score of < 1% indicates a very low exploitation probability, but the lack of regex validation makes exploitation straightforward for an account with rule‑creation rights. The vulnerability is not listed in CISA’s KEV catalog. An attacker can trigger a DoS by submitting the crafted input, which may impact availability for all users of the affected instance.
OpenCVE Enrichment