CRITICAL10.0CVE-2026-34976Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization from 0, < 25.3.1
CRITICAL9.8CVE-2026-41492Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars from 0, < 25.3.3
CRITICAL9.4CVE-2026-40173Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints from 0, < 25.3.2
CRITICAL9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field in github.com/dgraph-io/dgraph
from 0, < 25.3.3
CRITICAL9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
from 0, < 25.3.3
HIGH7.5Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query in github.com/dgraph-io/dgraph
from 0, < 25.3.4
HIGH7.5Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query in github.com/dgraph-io/dgraph
from 0, < 25.3.4