Currently, the fields in the query string are not sanitized for special characters in Fedora Koji
Upstream CVE info -- https://docs.pagure.org/koji/CVEs/CVE-2024-9427/