Vulnerabilidades en dgraph-io
9 resultadosAnálisis Vexday
A Dgraph registra 8 vulnerabilidades no Vexday, com 6 classificadas como críticas, porém nenhuma está sob ataque ativo no momento. O risco é moderado pelo padrão de descoberta recente — 2 CVEs nos últimos 90 dias — sugerindo exposição contínua de fragilidades em lógica de acesso (CWE-943), que demandam atenção prioritária em ambientes de produção ainda que não haja exploração confirmada.
CVE-2026-41492CRITICALUnauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars in DgraphEPSS 3.1%CVE-2026-40173CRITICALDgraph: Unauthenticated pprof endpoint leaks admin auth tokenEPSS 0.5%CVE-2026-41327CRITICALDgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition FieldEPSS 0.5%CVE-2026-34976CRITICALDgraph Affected by Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing AuthorizationEPSS 0.5%CVE-2026-41328CRITICALDgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang FieldEPSS 0.4%CVE-2026-54061CRITICALDgraph Alpha group stores can be replaced via unauthenticated external snapshot importEPSS 0.4%CVE-2026-44840HIGHDgraph Vulnerable to DQL Injection via checkUserPassword GraphQL QueryEPSS 0.4%CVE-2026-63637HIGHDgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriterEPSS 0.2%CVE-2023-31135LOWDgraph Audit Log Encryption nonce reuseEPSS 0.2%