tag
JSON:API
CVE-2026-9082 / SA-CORE-2026-004
web
CRITICAL
KEV
EPSS 88%
Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)
CVE-2026-9082 is an unauthenticated SQL injection in Drupal Core's PostgreSQL entity-query handling for JSON:API filters. User-controlled array keys are used to build SQL placeholder names without proper sanitization, enabling injection into generated SQL. On…
Patched
2026-05-30