Description
Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the REGEXP implementation registered by packages/core/src/service/helpers/list-query-builder/list-query-builder.ts, and better-sqlite3 and sqljs evaluate it synchronously in the Node.js event loop. ShopProductsResolver.products is publicly reachable, so one nested-quantifier pattern can block request processing and make the storefront and admin API unavailable, while repeated requests can sustain denial of service. PostgreSQL and MySQL or MariaDB deployments do not execute this regular expression in the Node.js event loop. This issue is fixed in version 3.6.5.
Published: 2026-09-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Vendure’s public Shop GraphQL API accepted user‑supplied regular expression patterns through the StringOperators.regex field. On SQLite and sqljs backends the raw pattern was executed synchronously by the Node.js event loop, allowing an unauthenticated caller to supply a catastrophically backtracking expression. A single nested‑quantifier pattern could block request processing long enough to halt the storefront and admin API, and repeated requests could sustain a denial‑of‑service event loop.

Affected Systems

These findings apply to Vendure HQ’s headless commerce platform, specifically versions prior to 3.6.5. The vulnerability exists when using SQLite or the bundled sqljs backend; deployments on PostgreSQL, MySQL, or MariaDB are unaffected.

Risk and Exploitability

The CVSS score reflects a high impact for denial of service, with a base score of 7.5. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. An attacker needs only to authenticate? false; the vulnerability is fully unauthenticated, simply constructing a malicious GraphQL query containing a backtracking regex via the regex operator. Should the attacker succeed, the target’s event loop will stall, rendering the public and private APIs unusable until the request completes or is forcibly terminated. The absence of an exploit in common attack suites and the lack of a KEV listing suggest moderate exploitation risk, but the high severity warrants rapid remediation.

Generated by OpenCVE AI on September 17, 2026 at 21:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Vendure to version 3.6.5 or later.
  • Restrict the Shop GraphQL API to authenticated requests or limit traffic to known IP addresses.
  • Implement rate limiting or query throttling on the GraphQL endpoint and monitor for high‑latency or repeated regex query patterns.

Generated by OpenCVE AI on September 17, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jgm3-qmp2-c4p7 Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Vendure
Vendure vendure
Vendors & Products Vendure
Vendure vendure

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the REGEXP implementation registered by packages/core/src/service/helpers/list-query-builder/list-query-builder.ts, and better-sqlite3 and sqljs evaluate it synchronously in the Node.js event loop. ShopProductsResolver.products is publicly reachable, so one nested-quantifier pattern can block request processing and make the storefront and admin API unavailable, while repeated requests can sustain denial of service. PostgreSQL and MySQL or MariaDB deployments do not execute this regular expression in the Node.js event loop. This issue is fixed in version 3.6.5.
Title Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:04:11.699Z

Reserved: 2026-07-16T21:37:45.768Z

Link: CVE-2026-63460

cve-icon Vulnrichment

Updated: 2026-09-17T15:03:47.767Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:49.447

Modified: 2026-09-17T21:16:02.560

Link: CVE-2026-63460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:30:15Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity