VulnSea

dgraph-io has 7 CVEs on record. Disclosures have slowed: 2 in the last 90 days after 5 in the 90 before. The busiest recent month was April 2026 with 5. The median CVSS is 9.1 (critical), with 6 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.1
Publish → KEV
Last 90 days
2 prev 5

Weakness classes

Products

  • github.com/dgraph-io/dgraph/v25 7
7
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

dgraph-io vulnerabilities

CVEs affecting dgraph-io, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-54061Critical· 9.1
1mo ago

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.58%via GHSA
CVE-2026-44840High· 7.5PoC
2mo ago

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query

Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.49%via GHSA
CVE-2026-41327Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field

Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.49%via OSV
CVE-2026-41492Critical· 9.8PoC
5mo ago

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars

Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 3.1%via OSV
CVE-2026-41328Critical· 9.1
5mo ago

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field

Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.41%via OSV
CVE-2026-40173Critical· 9.4
5mo ago

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

Dgraph: Unauthenticated /debug/pprof/cmdline discloses admin auth token, enabling unauthorized access to protected Alpha admin endpoints

Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.51%via OSV
CVE-2026-34976Critical· 10.0PoC
5mo ago

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization

Abyssaldgraph-io · github.com/dgraph-io/dgraph/v25EPSS 2.0%via OSV
dgraph-io vulnerabilities (CVEs) · VulnSea