{"id":"CVE-2026-73976","title":"djehuty is a research data repository system developed by 4TU.ResearchData","summary":"djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected qu…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-943"],"vendor":"4TUResearchData","product":"djehuty","affected":["djehuty < 26.3.2"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T18:17:27.550","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73976","references":[{"url":"https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2","label":"security-advisories@github.com"},{"url":"https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p","label":"security-advisories@github.com"},{"url":"https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T17:55:44.494192Z"},"cvssSource":"cna","ingestedAt":"2026-10-01T18:55:42.377Z","epss":0.00356,"epssPercentile":0.26989,"slug":"CVE-2026-73976","body":"## Overview\n\ndjehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}