VYPR

Magistrala

by Magistrala

CVEs (1)

  • CVE-2026-71276Aug 5, 2026
    risk 0.00cvss epss

    Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf() in both the PostgreSQL reader…