Gray Hats@the_yellow_fallPatch
Dgraph CVE‑2026‑40173 leaks admin tokens via unauthenticated debug endpoints, a critical CVSS 9.4 flaw enabling full DB takeover; a patch is available and recommended.
PulsePatch.io@pulsepatchioDisclosure
The text announces a critical admin token disclosure vulnerability in Dgraph, offers a mitigation by restricting network access, and provides minimal technical context without any PoC or exploit details.
CCB Alert@CCBalertPatch
The tweet informs of a critical credential disclosure vulnerability (CVE‑2026‑40173) affecting Dgraph’s GraphQL API, highlights token validation bypass, and advises restricting network access as a temporary mitigation until a patch is released.
CVE@CVEnewDisclosure
The CVE notes an unauthenticated credential disclosure in Dgraph versions 25.3.1 and earlier via the /debug/pprof endpoint.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A concise CVE disclosure describing unauthenticated credential disclosure in Dgraph versions prior to 25.3.1, with no PoC or exploit information included.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑40173, noting that an unauthenticated Go pprof debug endpoint can expose admin tokens via command‑line exposure, effectively turning it into a credential vending machine.