CVE-2026-41328Disclosure(dgraph / dgraph)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch dgraph dgraph systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configuration where ACL is not enabled. The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with @unique @index(exact) @lang via /alter (also unauthenticated in default config). The second sends a crafted JSON mutation to /mutate?commitNow=true where a JSON key contains the predicate name followed by @ and a DQL injection payload in the language tag position. The injection exploits the addQueryIfUnique function in edgraph/server.go, which constructs DQL queries using fmt.Sprintf with unsanitized predicateName that includes the raw pred.Lang value. The Lang field is extracted from JSON mutation keys by x.PredicateLang(), which splits on @, and is never validated by any function in the codebase. The attacker injects a closing parenthesis to escape the eq() function, adds an arbitrary named query block, and uses a # comment to neutralize trailing template syntax. The injected query executes server-side and its results are returned in the HTTP response. This vulnerability is fixed in 25.3.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dgraph

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
dgraph

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Mentions · 2026-05-22: 1Active Exploitation · 2026-04-26: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-22: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-22: 104-2404-2504-2605-22
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-04-261
Active Exploitation1
2026-05-221
Patch1
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Patch

    A previous patch to CVE-2026-41328 blocked the /debug/pprof/cmdline endpoint but only via explicit URL matching: Dgraph's Incomplete Security Patch Leaks Admin Tokens: Critical /debug/vars Flaw (CVE-2026-41492)

    Post summary

    The text highlights an incomplete patch for CVE‑2026‑41328 and a critical flaw in Dgraph’s /debug/vars endpoint that leaks admin tokens.

    1000058
    227 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Dgraph CVE-2026-41328 is under active exploitation—attackers can perform full database exfiltration via DQL injection. Patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #Ransomware #Malware https://t.co/vODJPV0O96

    Post summary

    Dgraph CVE-2026-41328 is being actively exploited through DQL injection, enabling complete database exfiltration, and a patch has been released to mitigate this risk.

    0000049
    57 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41328 Unauthenticated DQL Injection in Dgraph Prior to Version 25.3.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41328

    Post summary

    The note highlights CVE-2026-41328 as an unauthenticated DQL injection vulnerability in Dgraph versions earlier than 25.3.3, but provides no PoC, exploit details, mitigation, or evidence of active exploitation.

    0000044
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41328 Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read acce… https://www.cve.org/CVERecord?id=CVE-2026-41328

    Post summary

    The excerpt provides a brief disclosure of CVE-2026-41328, noting unauthenticated full read access in Dgraph versions before 25.3.3, but lacks details on exploits, patches, or active attacks.

    0000091
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdgraphdgraph-go-

Explore more