top of page
perceptive_background_267k.jpg

Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gR…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 15:06:43

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Identity & Access, Web Technologies

CVE-2026-54061 affects Dgraph, an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes snapshot import RPCs on the public gRPC port 9080 without any authentication or authorization controls. An unauthenticated remote attacker can exploit this by calling StreamExtSnapshot to send arbitrary Badger stream data to the target group's data store. Before processing the stream, the receiver invokes Prepare(), which deletes and replaces all existing database data, enabling complete data destruction or replacement. This represents a critical data integrity and availability risk for any exposed Dgraph instance. The vulnerability has been patched in version 25.3.5. Users are strongly advised to upgrade immediately to mitigate the risk of unauthorized data manipulation or destruction.

Technical details

Mitigation steps:

Affected products:

Dgraph

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page