<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 00:16:20 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-292972</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-292972</link>
      <description>EUVD-2026-292972</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-292972</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41328</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41328</link>
      <description>&lt;p&gt;Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph&amp;#39;s default configuration where ACL is not enabled. The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with @unique @index(exact) @lang via /alter (also unauthenticated in default config). The second sends a crafted JSON mutation to /mutate?commitNow=true where a JSON key contains the predicate name followed by @ and a DQL injection payload in the language tag position. The injection exploits the addQueryIfUnique function in edgraph/server.go, which constructs DQL queries using fmt.Sprintf with unsanitized predicateName that includes the raw pred.Lang value. The Lang field is extracted from JSON mutation keys by x.PredicateLang(), which splits on @, and is never validated by any function in the codebase. The attacker injects a closing parenthesis to escape the eq() function, adds an arbitrary named query block, and uses a # comment to neutralize trailing template syntax. The injected query executes server-side and its results are returned in the HTTP response. This vulnerability is fixed in 25.3.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph&amp;#39;s default configuration where ACL is not enabled. The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with @unique @index(exact) @lang via /alter (also unauthenticated in default config). The second sends a crafted JSON mutation to /mutate?commitNow=true where a JSON key contains the predicate name followed by @ and a DQL injection payload in the language tag position. The injection exploits the addQueryIfUnique function in edgraph/server.go, which constructs DQL queries using fmt.Sprintf with unsanitized predicateName that includes the raw pred.Lang value. The Lang field is extracted from JSON mutation keys by x.PredicateLang(), which splits on @, and is never validated by any function in the codebase. The attacker injects a closing parenthesis to escape the eq() function, adds an arbitrary named query block, and uses a # comment to neutralize trailing template syntax. The injected query executes server-side and its results are returned in the HTTP response. This vulnerability is fixed in 25.3.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41328</guid>
    </item>
    <item>
      <title>GHSA-x92x-px7w-4gx4 — Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x92x-px7w-4gx4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dgraph-io/dgraph/v25, Go: github.com/dgraph-io/dgraph/v24, Go: github.com/dgraph-io/dgraph&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph&amp;#39;s default configuration where ACL is not enabled.&lt;/p&gt;
&lt;p&gt;The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with `@unique @index(exact) @lang` via `/alter` (also unauthenticated in default config). The second sends a crafted JSON mutation to `/mutate?commitNow=true` where a JSON key contains the predicate name followed by `@` and a DQL injection payload in the language tag position.&lt;/p&gt;
&lt;p&gt;The injection exploits the `addQueryIfUnique` function in `edgraph/server.go`, which constructs DQL queries using `fmt.Sprintf` with unsanitized `predicateName` that includes the raw `pred.Lang` value. The `Lang` field is extracted from JSON mutation keys by `x.PredicateLang()`, which splits on `@`, and is never validated by any function in the codebase. The attacker injects a closing parenthesis to escape the `eq()` function, adds an arbitrary named query block, and uses a `#` comment to neutralize trailing template syntax. The injected query executes server-side and its results are returned in the HTTP response.&lt;/p&gt;
&lt;p&gt;POC clip:&lt;/p&gt;
&lt;p&gt;https://github.com/user-attachments/assets/bbfb7bba-c957-4b57-b534-48a958314186&lt;/p&gt;
&lt;p&gt;## 2. CVSS Score&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 9.1 (Critical)**&lt;/p&gt;
&lt;p&gt;```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
```&lt;/p&gt;
&lt;p&gt;| Metric              | Value     | Rationale…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/dgraph-io/dgraph/v25, Go: github.com/dgraph-io/dgraph/v24, Go: github.com/dgraph-io/dgraph&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every piece of data in the database. This affects Dgraph&amp;#39;s default configuration where ACL is not enabled.&lt;/p&gt;
&lt;p&gt;The attack requires two HTTP POSTs to port 8080. The first sets up a schema predicate with `@unique @index(exact) @lang` via `/alter` (also unauthenticated in default config). The second sends a crafted JSON mutation to `/mutate?commitNow=true` where a JSON key contains the predicate name followed by `@` and a DQL injection payload in the language tag position.&lt;/p&gt;
&lt;p&gt;The injection exploits the `addQueryIfUnique` function in `edgraph/server.go`, which constructs DQL queries using `fmt.Sprintf` with unsanitized `predicateName` that includes the raw `pred.Lang` value. The `Lang` field is extracted from JSON mutation keys by `x.PredicateLang()`, which splits on `@`, and is never validated by any function in the codebase. The attacker injects a closing parenthesis to escape the `eq()` function, adds an arbitrary named query block, and uses a `#` comment to neutralize trailing template syntax. The injected query executes server-side and its results are returned in the HTTP response.&lt;/p&gt;
&lt;p&gt;POC clip:&lt;/p&gt;
&lt;p&gt;https://github.com/user-attachments/assets/bbfb7bba-c957-4b57-b534-48a958314186&lt;/p&gt;
&lt;p&gt;## 2. CVSS Score&lt;/p&gt;
&lt;p&gt;**CVSS 3.1: 9.1 (Critical)**&lt;/p&gt;
&lt;p&gt;```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
```&lt;/p&gt;
&lt;p&gt;| Metric              | Value     | Rationale…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x92x-px7w-4gx4</guid>
    </item>
  </channel>
</rss>
