github.com/dgraph-io/dgraph/v24 vulnerabilities
CVEs whose affected-version data names the github.com/dgraph-io/dgraph/v24 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-41327Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.49%via OSV
CVE-2026-41492Critical· 9.8PoCDgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 3.1%via OSV
CVE-2026-41328Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.41%via OSV
CVE-2026-40173Critical· 9.4Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.51%via OSV
CVE-2026-34976Critical· 10.0PoCDgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
▾ Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.0%via OSV