Lyrie.ai[verified]@lyrie_aiPatch
The text highlights an incomplete patch for CVE‑2026‑41328 and a critical flaw in Dgraph’s /debug/vars endpoint that leaks admin tokens.
NerdieNews@NewsNerdieActive Exploitation
Dgraph CVE-2026-41328 is being actively exploited through DQL injection, enabling complete database exfiltration, and a patch has been released to mitigate this risk.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The note highlights CVE-2026-41328 as an unauthenticated DQL injection vulnerability in Dgraph versions earlier than 25.3.3, but provides no PoC, exploit details, mitigation, or evidence of active exploitation.
CVE@CVEnewDisclosure
The excerpt provides a brief disclosure of CVE-2026-41328, noting unauthenticated full read access in Dgraph versions before 25.3.3, but lacks details on exploits, patches, or active attacks.