VulnTracker[verified]@vuln_trackerGeneral
The tweet points readers to a vulnerability tracker page for CVE-2026-26198 but provides no further information.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
The tweet warns of a critical SQL injection in Ormar v0.9.9–0.22.0 that allows unauthenticated data reading and urges users to upgrade to v0.23.0+.
CVETodo[verified]@CveTodoDisclosure
CVE-2026-26198 is a critical SQL injection flaw in the Ormar ORM caused by unsanitized column names in aggregate queries, affecting versions 0.9.9 through 0.22.0.
Gray Hats@the_yellow_fallPatch
The post announces a critical SQL injection flaw in ormar Python ORM (CVE-2026-26198) that permits unauthenticated database leakage and urges users to update to version 0.23.0.
CVEFind.com@CveFindComPatch
CVE‑2026‑26198 in Ormar permits full database reads; a patch is available in version 0.23.0.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-26198, a critical vulnerability in Ormar ORM affecting aggregate queries in versions 0.9.9–0.22.0, with CVSS 9.8, but no PoC, exploit, or patch details are provided.
CRAC Learning - Tech@cracbotDisclosure
The post announces the critical CVE-2026-26198 affecting Ormar's aggregate queries, providing severity but no PoC, exploit, or patch details.
PulsePatch.io@pulsepatchioPatch
The post announces a critical SQL injection in ormar ORM and advises updating to version 0.23.0 or later to mitigate.