CVE-2026-34400

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
31/03/2026
Last modified:
10/04/2026

Description

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alerta_project:alerta:*:*:*:*:*:*:*:* 9.1.0 (excluding)