Found in connection with #35916. No changes file as this is effectively an unreleased bugfix (will cherry-pick this). No updates to tests because tests don't test index existence. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements)