In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
{ "github_reviewed_at": "2022-06-25T07:23:27Z", "severity": "HIGH", "nvd_published_at": "2022-06-23T17:15:00Z", "github_reviewed": true, "cwe_ids": [] }