
🚨High - Dgraph GraphQL Rewriter DQL Injection via regexp Filters (CVE-2026-63637) In Dgraph’s GraphQL query rewriter, regexp filter strings in /pattern/flags form are inserted into generated DQL without proper quoting/validation, enabling crafted GraphQL query/mutation filters to inject DQL operators. Impact: unintended node disclosure and broadened mutation/delete target sets. 👉Affected: dgraph < 25.3.8 | Upgrade to 25.3.8
Post summary
The advisory discloses a DQL injection vulnerability in Dgraph’s GraphQL rewriter via regular expression filters, detailing its impact and recommending an upgrade to version 25.3.8.
