CVE-2026-63637: CWE-943: Improper Neutralization of Special Elements in Data Query Logic in dgraph-io dgraph
CVE-2026-63637 is a high-severity vulnerability in the open source distributed GraphQL database dgraph-io dgraph. Versions prior to 25.3.8 improperly handle regexp filter strings in GraphQL queries, allowing injection of DQL operators. This can lead to unintended data disclosure and unauthorized modification or deletion of nodes. The issue is fixed in version 25.3.8.
AI Analysis
Technical Summary
Dgraph versions before 25.3.8 contain a vulnerability where the function maybeQuoteArg in graphql/resolve/query_rewriter.go fails to properly quote or validate the /pattern/flags form in regexp filter strings. This improper neutralization of special elements in data query logic (CWE-943) enables crafted GraphQL queries or mutations to inject Dgraph Query Language (DQL) operators. Exploiting this flaw can disclose unintended nodes and expand the scope of modification and deletion operations beyond intended targets. The vulnerability has a CVSS 3.1 score of 8.6, indicating high severity. The issue is resolved in version 25.3.8.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject DQL operators via crafted GraphQL query or mutation filters, potentially leading to unauthorized data disclosure and unauthorized modification or deletion of data nodes. This compromises confidentiality, integrity, and availability of the affected database.
Mitigation Recommendations
Upgrade dgraph to version 25.3.8 or later, where this vulnerability is fixed. Patch status is confirmed by the vendor advisory indicating the fix in 25.3.8. No additional mitigations are specified.
CVE-2026-63637: CWE-943: Improper Neutralization of Special Elements in Data Query Logic in dgraph-io dgraph
Description
CVE-2026-63637 is a high-severity vulnerability in the open source distributed GraphQL database dgraph-io dgraph. Versions prior to 25.3.8 improperly handle regexp filter strings in GraphQL queries, allowing injection of DQL operators. This can lead to unintended data disclosure and unauthorized modification or deletion of nodes. The issue is fixed in version 25.3.8.
CVSS v3.1
Score 8.6high
Affected software
dgraph-io
dgraph
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Dgraph versions before 25.3.8 contain a vulnerability where the function maybeQuoteArg in graphql/resolve/query_rewriter.go fails to properly quote or validate the /pattern/flags form in regexp filter strings. This improper neutralization of special elements in data query logic (CWE-943) enables crafted GraphQL queries or mutations to inject Dgraph Query Language (DQL) operators. Exploiting this flaw can disclose unintended nodes and expand the scope of modification and deletion operations beyond intended targets. The vulnerability has a CVSS 3.1 score of 8.6, indicating high severity. The issue is resolved in version 25.3.8.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject DQL operators via crafted GraphQL query or mutation filters, potentially leading to unauthorized data disclosure and unauthorized modification or deletion of data nodes. This compromises confidentiality, integrity, and availability of the affected database.
Mitigation Recommendations
Upgrade dgraph to version 25.3.8 or later, where this vulnerability is fixed. Patch status is confirmed by the vendor advisory indicating the fix in 25.3.8. No additional mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-17T14:11:15.482Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a750707bf8831d5395f5ac3
Added to database: 08/06/2026, 22:13:27 UTC
Last enriched: 08/14/2026, 16:10:28 UTC
Last updated: 09/21/2026, 22:01:36 UTC
Views: 33
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.