Unauthenticated Credential Disclosure in Dgraph Database by Dgraph.io
CVE-2026-40173
9.4CRITICAL
What is CVE-2026-40173?
Dgraph, an open source distributed GraphQL database, has a vulnerability where the /debug/pprof/cmdline endpoint is accessible without authentication. This exposure allows an attacker to retrieve sensitive information, specifically the admin token set via the --security 'token=...' startup option. With the leaked information, unauthorized users can exploit admin-only endpoints leading to potential configuration changes and operational control within the environment. This vulnerability has been remedied in version 25.3.2.
Affected Version(s)
dgraph < 25.3.2
