8.6.36 (2026-03-11) Bug Fixes SQL injection via query field name when using PostgreSQL (GHSA-c442-97qw-j6c6) (#10182) (0b0398b)