alerta-server vulnerabilities
CVEs whose affected-version data names the alerta-server package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-34400Mediumalerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API
▾ Sunlitalerta-server · alerta-serverEPSS 0.51%via OSV
CVE-2020-26214Critical· 9.1PoCLDAP authentication bypass with empty password
LDAP authentication bypass with empty password
▾ Abyssalalerta-server · alerta-serverEPSS 66%via OSV