Dgraph is a graph database platform whose narrow but prominent product footprint sits in the data-layer of modern application architectures, handling queries and storing sensitive relationship data. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code; the recurring weakness classes—including sensitive information exposure, improper query neutralization, weak encryption, debug-code information leakage, and inadequate credential protection—reflect the authentication, encryption, and injection-resistance demands of a query-processing engine. Defenders should treat Dgraph advisories as high-priority for any deployment handling sensitive or relational data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dgraph over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41492CRITICAL Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through the unauthenticated /debug/vars endpoint on Alpha. Because | Apr 24, 2026 | 9.8 | 53 | NO | YES |
CVE-2026-41328CRITICAL Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every pi | Apr 24, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-41327CRITICAL Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an unauthenticated attacker full read access to every pi | Apr 24, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-34976CRITICAL Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from the authorization middleware config (admin.go), making it c | Apr 6, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-40173CRITICAL Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpo | Apr 15, 2026 | 9.4 | 32 | NO | NO |
CVE-2023-31135MEDIUM Dgraph is an open source distributed GraphQL database. Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. The first 12 bytes come from a base | May 17, 2023 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dgraph.
Media articles that mention a CVE ID that affects a product developed by Dgraph — matched by CVE ID, not by vendor name.