Dgraph disclosed two high-severity vulnerabilities that allowed unauthenticated attackers to compromise deployments through exposed administrative interfaces and query injection. CVE-2026-40173 affects Dgraph 25.3.1 and earlier and leaks the full process command line through the unauthenticated /debug/pprof/cmdline endpoint, exposing admin tokens passed with the startup flag --security "token=...". Attackers can reuse the stolen token in the X-Dgraph-AuthToken header to reach admin-only endpoints such as /admin/config/cache_mb, enabling unauthorized configuration changes and other privileged operational actions when the Alpha HTTP port is reachable.
A second flaw, CVE-2026-41327, affects versions prior to 25.3.3 and allows pre-authentication full read access to databases running with the default configuration and ACL disabled. The bug is caused by unsafe concatenation of a crafted cond field in an upsert mutation sent to /mutate?commitNow=true, which enables DQL injection and returns server-side query results directly in the HTTP response. Dgraph addressed the issues in 25.3.2 and 25.3.3, respectively, underscoring the risk to internet-exposed instances that had not restricted debug access or hardened authentication settings.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Dgraph fixed CVE-2026-41327 in version 25.3.3. The patch addressed unsafe concatenation in the upsert condition field that allowed server-side DQL query injection and full read access to database contents.
On April 24, 2026, CVE-2026-41327 was disclosed affecting Dgraph versions prior to 25.3.3. The vulnerability allows an unauthenticated attacker to exfiltrate all database data in default configurations without ACL by injecting DQL through the upsert cond field.
Dgraph addressed CVE-2026-40173 in release 25.3.2. The flaw exposed the process command line through an unauthenticated /debug/pprof/cmdline endpoint, which could leak the admin auth token and enable unauthorized access to admin-only endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.