dgraph-io has 7 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 5 in the 90 before. The busiest recent month was April 2026 with 5. The median CVSS is 9.1 (critical), with 6 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 5
Worst active — by depth score
CVE-2026-41492Critical· 9.8Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars67CVE-2026-34976Critical· 10.0Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization67CVE-2026-44840High· 7.5Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query53CVE-2026-40173Critical· 9.4Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints52CVE-2026-54061Critical· 9.1Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import50
dgraph-io vulnerabilities
CVEs affecting dgraph-io, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-54061Critical· 9.1Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import
CVE-2026-44840High· 7.5PoCDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query
CVE-2026-41327Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
CVE-2026-41492Critical· 9.8PoCDgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
CVE-2026-41328Critical· 9.1Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
CVE-2026-40173Critical· 9.4Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints
CVE-2026-34976Critical· 10.0PoCDgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization
Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization