Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Go/github.com/dgraph-io/dgraph — 7 CVEs · VulnScope
pkg:Go/
github.com/dgraph-io/dgraph
7 total CVEs
CRITICAL
5
HIGH
1
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
10.0
CVE-2026-34976
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
from 0, <= 1.2.8
CRITICAL
9.8
CVE-2026-41492
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
from 0, <= 1.2.8
CRITICAL
9.4
CVE-2026-40173
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
from 0, <= 1.2.8
CRITICAL
9.1
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field in github.com/dgraph-io/dgraph
from 0, <= 1.2.8
CRITICAL
9.1
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
from 0, <= 1.2.8
HIGH
7.5
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query in github.com/dgraph-io/dgraph
from 0
MEDIUM
5.5
Dgraph Audit Log Encryption Vulnerability
from 0, < 23.0.0
CVE-2026-41328
CVE-2026-41327
CVE-2026-44840
CVE-2023-31135