Dgraph

Dgraph

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.19%
  • Veröffentlicht 24.04.2026 18:29:40
  • Zuletzt bearbeitet 28.04.2026 18:28:30

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." st...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 24.04.2026 18:27:51
  • Zuletzt bearbeitet 28.04.2026 18:31:22

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configurati...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 24.04.2026 18:25:43
  • Zuletzt bearbeitet 28.04.2026 18:31:09

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph's default configurati...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 15.04.2026 20:40:47
  • Zuletzt bearbeitet 25.04.2026 18:27:50

Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authenticat...

Medienbericht Exploit
  • EPSS 0.45%
  • Veröffentlicht 06.04.2026 16:12:43
  • Zuletzt bearbeitet 22.04.2026 19:51:26

Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which r...

  • EPSS 0.15%
  • Veröffentlicht 17.05.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 08:01:27

Dgraph is an open source distributed GraphQL database. Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. The first 12 bytes come from a baseIv which is initialized when an audit log is created. The last 4 bytes...