SPARQL Injection Vulnerability in djehuty Data Repository by 4TU.ResearchData
CVE-2026-73976

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-73976?

The djehuty research data repository by 4TU.ResearchData is vulnerable to SPARQL injection, allowing unauthenticated users to manipulate search queries. Attackers can exploit this flaw through specific parameters to execute unauthorized extraction of data across graphs, potentially accessing sensitive drafts, private, or internal information in the RDF store. The vulnerability could also lead to denial of service by executing costly or malformed queries that overwhelm the SPARQL backend or web workers. The issue has been effectively addressed in version 26.3.2.

Affected Version(s)

djehuty < 26.3.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.