Search Results (1 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-34400 1 Alerta 1 Alerta 2026-04-02 N/A
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.