Back to search
CVE-2026-34400
Published: Mar 31, 2026
Modified: Apr 3, 2026
PUBLISHED
Description
Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.
| Vendor | Product | Versions |
|---|---|---|
alerta | alerta | affected < 9.1.0 |
Weaknesses (CWE)
References
https://github.com/alerta/alerta/security/advisories/GHSA-8prr-286p-4w7j
x_refsource_CONFIRM
https://github.com/alerta/alerta/pull/2040
x_refsource_MISC
https://github.com/alerta/alerta/pull/712
x_refsource_MISC
https://github.com/alerta/alerta/releases/tag/v9.1.0
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now