CVE-2026-39972 | dunglas mercure up to 0.21.x TopicSelectorStore improper validation of unsafe equivalence in input (GHSA-hwr4-mq23-wcv5)
A vulnerability identified as critical has been detected in dunglas mercure up to 0.21.x. Affected by this vulnerability is an unknown functionality of the component TopicSelectorStore. Performing a manipulation results in improper validation of unsafe equivalence in input.
This vulnerability is identified as CVE-2026-39972. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.