{
  "verdict": "confirmed",
  "issue_id": "CVE-2026-9082",
  "advisory": "SA-CORE-2026-004",
  "reproduced": true,
  "vulnerable_version": "11.3.9",
  "fixed_version": "11.3.10",
  "details": {
    "vulnerability_type": "SQL Injection",
    "cwe": "CWE-89",
    "affected_backend": "PostgreSQL",
    "exploit_vector": "JSON:API collection filter query parameter with malicious array key",
    "vulnerable_indicator": "HTTP 500 response with SQLSTATE[HY093] Invalid parameter number error",
    "fixed_indicator": "HTTP 200 response with normal JSON:API empty data array"
  },
  "logs": {
    "vulnerable_response": "logs/vulnerable_response.txt",
    "fixed_response": "logs/fixed_response.txt",
    "repro_output_1": "logs/repro_output.txt",
    "repro_output_2": "logs/repro_output_2.txt"
  },
  "timestamp": "2026-05-22T05:42:00Z"
}
