Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
pkg:Go/
github.com/dgraph-io/dgraph/v24
6 total CVEs
CRITICAL
5
HIGH
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
10.0
CVE-2026-34976
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
from 0, <= 24.0.5
CRITICAL
9.8
CVE-2026-41492
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
from 0, <= 24.1.8
CRITICAL
9.4
CVE-2026-40173
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
from 0, <= 24.1.7
CRITICAL
9.1
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field in github.com/dgraph-io/dgraph
from 0, <= 24.1.8
CRITICAL
9.1
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
from 0, <= 24.1.8
HIGH
7.5
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query in github.com/dgraph-io/dgraph
from 0
CVE-2026-41328
CVE-2026-41327
CVE-2026-44840
Go/github.com/dgraph-io/dgraph/v24 — 6 CVEs · VulnScope