logo

Critical SQL Injection Vulnerability Found in ‘ormar’ Python Library

ID: 569ed145-3595-52d5-8ef9-b4d12f04d8cd

STIX ID: report--569ed145-3595-52d5-8ef9-b4d12f04d8cd

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical SQL injection vulnerability (CVE-2026-26198, CVSS 9.8) was found in the ormar asynchronous Python ORM where user-supplied column names are passed directly into sqlalchemy.text() without sanitization; min() and max() can be abused to read entire databases across SQLite, PostgreSQL and MySQL. The flaw affects ormar versions 0.9.9 through 0.22.0, has broad impact given the library's widespread use in FastAPI and async applications, and was fixed in version 0.23.0 — administrators should audit and upgrade affected dependencies immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.