<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T18:11:09.702352+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333965</id>
    <title>EUVD-2026-333965</title>
    <updated>2026-10-06T18:11:09.763525+00:00</updated>
    <content>EUVD-2026-333965</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54061</id>
    <title>fkie_cve-2026-54061</title>
    <updated>2026-10-06T18:11:09.763568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rrwh-6jrq-wp5v</id>
    <title>GHSA-rrwh-6jrq-wp5v — Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import</title>
    <updated>2026-10-06T18:11:09.763608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/dgraph-io/dgraph/v25</p>
<p>## Summary</p>
<p>Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data to the target group’s store. In addition, the receiver calls `Prepare()` before processing the stream. This operation deletes and replaces the existing DB data.</p>
<p>## Root Cause</p>
<p>The root cause is that the RPCs used for external snapshot import are exposed through Alpha’s public gRPC service, but no administrator authorization check is performed before reaching destructive storage operations.</p>
<p>Streaming RPCs such as `StreamExtSnapshot` do not have a stream interceptor, and the RPC handlers do not perform their own authorization checks. As a result, an unauthenticated client that can reach the public gRPC port can start the import flow. Dgraph then calls Badger’s `StreamWriter.Prepare()` on the target group store. This operation deletes the existing database, allowing the attacker’s stream to potentially replace the store.</p>
<p>## Steps to Reproduce</p>
<p>Preconditions:</p>
<p>- A throwaway Dgraph Alpha is reachable on its public gRPC port, default `:9080`
- Public gRPC mTLS is not enabled
- No Dgraph ACL token, JWT, or gRPC `auth-token` metadata is used by the client</p>
<p>1. Start a throwaway standalone Dgraph instance from the tested build and insert synthetic data.</p>
<p>```bash
# Example if the tested source tree is built and tagged locally.
docker…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rrwh-6jrq-wp5v"/>
  </entry>
</feed>
