<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 09:59:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-281090</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-281090</link>
      <description>EUVD-2026-281090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-281090</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34976</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34976</link>
      <description>&lt;p&gt;Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restoreTenant executes with zero middleware. This mutation accepts attacker-controlled backup source URLs (including file:// for local filesystem access), S3/MinIO credentials, encryption key file paths, and Vault credential file paths. An unauthenticated attacker can overwrite the entire database, read server-side files, and perform SSRF. This vulnerability is fixed in 25.3.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it completely unauthenticated. Unlike the similar restore mutation which requires Guardian-of-Galaxy authentication, restoreTenant executes with zero middleware. This mutation accepts attacker-controlled backup source URLs (including file:// for local filesystem access), S3/MinIO credentials, encryption key file paths, and Vault credential file paths. An unauthenticated attacker can overwrite the entire database, read server-side files, and perform SSRF. This vulnerability is fixed in 25.3.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34976</guid>
    </item>
    <item>
      <title>GHSA-p5rh-vmhp-gvcw — Dgraph: Pre-Auth Database Overwrite + SSRF + File Read via restoreTenant Missing Authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p5rh-vmhp-gvcw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dgraph-io/dgraph/v25, Go: github.com/dgraph-io/dgraph/v24, Go: github.com/dgraph-io/dgraph&lt;/p&gt;
&lt;p&gt;The `restoreTenant` admin mutation is missing from the authorization middleware config (`admin.go:499-522`), making it completely unauthenticated. Unlike the similar `restore` mutation which requires Guardian-of-Galaxy authentication, `restoreTenant` executes with zero middleware.&lt;/p&gt;
&lt;p&gt;This mutation accepts attacker-controlled backup source URLs (including `file://` for local filesystem access), S3/MinIO credentials, encryption key file paths, and Vault credential file paths. An unauthenticated attacker can overwrite the entire database, read server-side files, and perform SSRF.&lt;/p&gt;
&lt;p&gt;## Authentication Bypass&lt;/p&gt;
&lt;p&gt;Every admin mutation has middleware configured in `adminMutationMWConfig` (`admin.go:499-522`) EXCEPT `restoreTenant`. The `restore` mutation has `gogMutMWs` (Guardian of Galaxy auth + IP whitelist + logging). `restoreTenant` is absent from the map.&lt;/p&gt;
&lt;p&gt;When middleware is looked up at `resolve/resolver.go:431`, the map returns nil. The `Then()` method at `resolve/middlewares.go:98` checks `len(mws) == 0` and returns the resolver directly, skipping all authentication, authorization, IP whitelisting, and audit logging.&lt;/p&gt;
&lt;p&gt;## PoC 1: Pre-Auth Database Overwrite&lt;/p&gt;
&lt;p&gt;The attacker hosts a crafted Dgraph backup on their own S3 bucket, then triggers a restore that overwrites the target namespace&amp;#39;s entire database:&lt;/p&gt;
&lt;p&gt;# No authentication headers needed. No X-Dgraph-AuthToken, no JWT, no Guardian credentials.
    curl -X POST http://dgraph-alpha:8080/admin \
      -H &amp;#34;Content-Type: application/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dgraph-io/dgraph/v25, Go: github.com/dgraph-io/dgraph/v24, Go: github.com/dgraph-io/dgraph&lt;/p&gt;
&lt;p&gt;The `restoreTenant` admin mutation is missing from the authorization middleware config (`admin.go:499-522`), making it completely unauthenticated. Unlike the similar `restore` mutation which requires Guardian-of-Galaxy authentication, `restoreTenant` executes with zero middleware.&lt;/p&gt;
&lt;p&gt;This mutation accepts attacker-controlled backup source URLs (including `file://` for local filesystem access), S3/MinIO credentials, encryption key file paths, and Vault credential file paths. An unauthenticated attacker can overwrite the entire database, read server-side files, and perform SSRF.&lt;/p&gt;
&lt;p&gt;## Authentication Bypass&lt;/p&gt;
&lt;p&gt;Every admin mutation has middleware configured in `adminMutationMWConfig` (`admin.go:499-522`) EXCEPT `restoreTenant`. The `restore` mutation has `gogMutMWs` (Guardian of Galaxy auth + IP whitelist + logging). `restoreTenant` is absent from the map.&lt;/p&gt;
&lt;p&gt;When middleware is looked up at `resolve/resolver.go:431`, the map returns nil. The `Then()` method at `resolve/middlewares.go:98` checks `len(mws) == 0` and returns the resolver directly, skipping all authentication, authorization, IP whitelisting, and audit logging.&lt;/p&gt;
&lt;p&gt;## PoC 1: Pre-Auth Database Overwrite&lt;/p&gt;
&lt;p&gt;The attacker hosts a crafted Dgraph backup on their own S3 bucket, then triggers a restore that overwrites the target namespace&amp;#39;s entire database:&lt;/p&gt;
&lt;p&gt;# No authentication headers needed. No X-Dgraph-AuthToken, no JWT, no Guardian credentials.
    curl -X POST http://dgraph-alpha:8080/admin \
      -H &amp;#34;Content-Type: application/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p5rh-vmhp-gvcw</guid>
    </item>
  </channel>
</rss>
