CVE-2026-71282 | ChirpStack up to 4.19.0-test.5 SQLite backend device.rs get_count/list sql injection

SecurityVulns

A vulnerability was found in ChirpStack up to 4.19.0-test.5. It has been declared as critical. Affected by this vulnerability is the function get_count/list of the file chirpstack/src/storage/device.rs of the component SQLite backend. Such manipulation of the argument k leads to sql injection.

This vulnerability is referenced as CVE-2026-71282. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More