<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T15:12:41.404762+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-292970</id>
    <title>EUVD-2026-292970</title>
    <updated>2026-10-06T15:12:41.695362+00:00</updated>
    <content>EUVD-2026-292970</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-292970"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41492</id>
    <title>fkie_cve-2026-41492</title>
    <updated>2026-10-06T15:12:41.695399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because the admin token is commonly supplied via the --security "token=..." startup flag, an unauthenticated attacker can retrieve that token and replay it in the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of the previously fixed /debug/pprof/cmdline issue, but the current fix is incomplete because it blocks only /debug/pprof/cmdline and still serves http.DefaultServeMux, which includes expvar's /debug/vars handler. This vulnerability is fixed in 25.3.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vvf7-6rmr-m29q</id>
    <title>GHSA-vvf7-6rmr-m29q — Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars</title>
    <updated>2026-10-06T15:12:41.695434+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/dgraph-io/dgraph/v25, Go: github.com/dgraph-io/dgraph/v24, Go: github.com/dgraph-io/dgraph</p>
<p>### Summary
Dgraph `v25.3.2` still exposes the process command line through the unauthenticated `/debug/vars` endpoint on Alpha. Because the admin token is commonly supplied via the `--security "token=..."` startup flag, an unauthenticated attacker can retrieve that token and replay it in the `X-Dgraph-AuthToken` header to access admin-only endpoints.</p>
<p>This is a variant of the previously fixed `/debug/pprof/cmdline` issue, but the current fix is incomplete because it blocks only `/debug/pprof/cmdline` and still serves `http.DefaultServeMux`, which includes `expvar`'s `/debug/vars` handler.</p>
<p>### Details
Alpha still exposes Go's default HTTP mux:</p>
<p>- `x/metrics.go`
  - imports `expvar`
  - initializes `Conf = expvar.NewMap("dgraph_config")`
- Go's `expvar` package automatically registers `/debug/vars`
- `expvar` publishes:
  - `cmdline = os.Args`
  - `memstats = runtime.Memstats`</p>
<p>Alpha's HTTP handler explicitly blocks only the old CVE path:</p>
<p>- `dgraph/cmd/alpha/run.go`
  - checks `if r.URL.Path == "/debug/pprof/cmdline"` and returns `404`
  - otherwise falls through to `http.DefaultServeMux.ServeHTTP(w, r)`</p>
<p>Admin endpoints still trust the leaked token:</p>
<p>- `dgraph/cmd/alpha/admin.go`
  - reads `X-Dgraph-AuthToken`
  - compares it to `worker.Config.AuthToken`
### PoC
1. Send an unauthenticated request to Alpha:</p>
<p>```http
GET /debug/vars HTTP/1.1
Host: target:8080
```</p>
<p>2. Parse the JSON response and read the `cmdline` field.</p>
<p>3. Extract the admin token from the startup arguments,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vvf7-6rmr-m29q"/>
  </entry>
</feed>
