top of page
perceptive_background_267k.jpg

Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoin…

Published:

23 april 2026 om 22:00:00

Alert date:

24 april 2026 om 20:03:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Web Technologies

Dgraph, an open source distributed GraphQL database, contains a vulnerability in versions prior to 25.3.3 that exposes the process command line through the unauthenticated /debug/vars endpoint. Attackers can retrieve admin tokens commonly supplied via startup flags and replay them using the X-Dgraph-AuthToken header to access admin-only endpoints. This is a variant of a previously fixed /debug/pprof/cmdline issue, but the fix was incomplete as it only blocked that specific endpoint while still serving http.DefaultServeMux. The vulnerability allows unauthenticated privilege escalation and is fixed in version 25.3.3.

Technical details

Mitigation steps:

Affected products:

Dgraph

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page