Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/dgraph-io/dgraph

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-63637 is a high-severity vulnerability in the open source distributed GraphQL database dgraph-io dgraph. Versions prior to 25.3.8 improperly handle regexp filter strings in GraphQL queries, allowing injection of DQL operators. This can lead to unintended data disclosure and unauthorized modification or deletion of nodes. The issue is fixed in version 25.3.8.

Join the discussion

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is vulnerable to DQL (Dgraph Query Language) injection. User-supplied password values are interpolated directly into a DQL `checkpwd()` query via `fmt.Sprintf` without any escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks. Version 25.3.4 patches the issue.

Join the discussion

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.

Join the discussion

Dgraph versions prior to 25.3.3 expose sensitive information via an unauthenticated /debug/vars endpoint on the Alpha component. This exposure includes the process command line, which often contains the admin token passed as a startup flag. An attacker can retrieve this token and use it to access admin-only endpoints by replaying it in the X-Dgraph-AuthToken header. This vulnerability is a variant of a previously fixed issue but was incompletely remediated. The vulnerability is fixed in version 25.3.3.

Join the discussion

A critical vulnerability (CVE-2026-41327) exists in dgraph-io dgraph versions prior to 25.3.3 where an unauthenticated attacker can gain full read access to all data in the database. This occurs due to improper neutralization of special elements in data query logic (CWE-943) in the cond field of an upsert mutation. The vulnerability arises because the cond value is concatenated directly into a DQL query string without proper escaping or validation, allowing injection of additional query blocks. The issue affects default configurations without ACL enabled. The vulnerability is fixed in version 25.3.3.

Join the discussion

CVE-2026-41328 is a critical vulnerability in dgraph-io dgraph versions prior to 25.3.3. It allows an unauthenticated attacker to gain full read access to all data in the database if Access Control Lists (ACL) are not enabled. The issue arises from improper neutralization of special elements in data query logic, enabling injection of malicious Dgraph Query Language payloads via crafted HTTP POST requests. This vulnerability is fixed in version 25.3.3.

Join the discussion

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line including the admin token configured via the --security "token=..." startup flag. An attacker can retrieve the leaked token and reuse it in the X-Dgraph-AuthToken header to gain unauthorized access to admin-only endpoints such as /admin/config/cache_mb, bypassing the adminAuthHandler token validation. This enables unauthorized privileged administrative access including configuration changes and operational control actions in any deployment where the Alpha HTTP port is reachable by untrusted parties. This issue has been fixed in version 25.3.2.

Join the discussion

CVE-2026-34976 is a critical authorization bypass vulnerability in dgraph-io's open source distributed GraphQL database, dgraph, affecting versions prior to 25.3.1. The restoreTenant admin mutation lacks authorization middleware, allowing unauthenticated attackers to execute it without restriction. This mutation accepts attacker-controlled inputs such as backup source URLs, S3/MinIO credentials, encryption key file paths, and Vault credential file paths. Exploitation can lead to full database overwrite, server-side file reading, and server-side request forgery (SSRF). The vulnerability is fixed in version 25.3.1. The product is a cloud service, and the vendor manages remediation for the hosted service.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/dgraph-io/dgraph
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses