logo

Dgraph’s Debug Endpoint Hands Over Admin Tokens to Anyone

ID: c917ee51-3a2c-51c2-8225-7a5bde38f2d8

STIX ID: report--c917ee51-3a2c-51c2-8225-7a5bde38f2d8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-19

Date Updated: 2026-05-05

Author: Ddos

...
...

A critical Dgraph vulnerability (CVE-2026-40173, CVSS 9.4) was disclosed: the default inclusion of net/http/pprof exposes /debug/pprof/cmdline without authentication, revealing the admin token in plaintext. An attacker with network access to the Alpha HTTP port can read the token and perform admin-level actions by supplying it in X-Dgraph-AuthToken; all versions up to v25.3.1 are affected and a fix was released in v25.3.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.