CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34400

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-89

Description

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.

Affected packages

PyPI alerta-server 0 → 9.1.0

References

Status: profiled · ingested 2026-07-25T00:00:18.000Z