Skip to content
Threat Feed

Product

Dgraph

5 briefs RSS
critical advisory

Unauthenticated Remote Data Replacement in Dgraph Alpha

An unauthenticated remote attacker can leverage the Dgraph Alpha gRPC interface to clear or replace internal database group stores, potentially leading to unauthorized data modification and privilege escalation.

Dgraph
2t 1c
critical advisory

Dgraph Pre-Auth DQL Injection Vulnerability

A pre-authentication DQL injection vulnerability in Dgraph's `/mutate` endpoint, when ACL is disabled, allows attackers to exfiltrate the entire database by crafting a malicious `cond` field in an upsert mutation.

Dgraph dql-injection injection database-exfiltration
1r 1t
critical advisory

Dgraph Unauthenticated Admin Token Disclosure via /debug/vars

Dgraph versions prior to 25.3.3 expose the admin token via the `/debug/vars` endpoint, allowing unauthenticated attackers to bypass authentication and gain administrative access.

Dgraph authentication-bypass admin-token-disclosure
3r 2t
critical advisory

Dgraph Unauthenticated Admin Token Disclosure Vulnerability

Dgraph versions 25.3.1 and prior expose the admin token via an unauthenticated endpoint, enabling attackers to gain administrative access by reusing the leaked token.

Dgraph credential-disclosure privilege-escalation graphql
2r 2t 1c
critical advisory

Dgraph Pre-Auth Full Database Exfiltration via DQL Injection

A pre-authentication DQL injection vulnerability in Dgraph's default configuration allows attackers to exfiltrate the entire database by crafting malicious JSON mutations to the `/mutate` endpoint, exploiting unsanitized language tags in predicates.

Dgraph dql-injection vulnerability
2r 6t