


Perceptive Security
SOC/SIEM Consultancy

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoin…
Published:
23 April 2026 at 22:00:00
Alert date:
24 April 2026 at 20:03:09
Source:
nvd.nist.gov
Database & Storage, Web Technologies
Dgraph, an open source distributed GraphQL database, contains a vulnerability in versions prior to 25.3.3 that exposes the process command line through the unauthenticated /debug/vars endpoint. Attackers can retrieve admin tokens commonly supplied via startup flags and replay them using the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of a previously fixed /debug/pprof/cmdline issue, but the fix was incomplete as it only blocked that specific endpoint while still serving http.DefaultServeMux. The vulnerability allows unauthenticated privilege escalation and is fixed in version 25.3.3.
Technical details
Mitigation steps:
Affected products:
Dgraph
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41492
https://github.com/dgraph-io/dgraph/releases/tag/v25.3.3
https://github.com/dgraph-io/dgraph/security/advisories/GHSA-vvf7-6rmr-m29q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
