THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jgm3-qmp2-c4p7 (high) — Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

[GHSA] GHSA-jgm3-qmp2-c4p7 (high) — Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

medgithub_advisoriesPublished 2026-09-17

GHSA-jgm3-qmp2-c4p7 Severity: high CVE: CVE-2026-63460

Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

### Summary

> [!IMPORTANT] > Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.

The `StringOperators.regex` filter expo

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jgm3-qmp2-c4p7