GO-2026-5837
DQL injection via checkUserPassword GraphQL query in github.com/dgraph-io/dgraph
Quick fix
GO-2026-5837 — github.com/dgraph-io/dgraph/v25: upgrade to the fixed version with the command below.
go get github.com/dgraph-io/dgraph/v25@v25.3.4Details
The checkUserPassword GraphQL query in Dgraph is vulnerable to Dgraph Query Language (DQL) injection. User-supplied password values are interpolated directly into a DQL checkpwd query without escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/dgraph-io/dgraph (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/hypermodeinc/dgraph/v24 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 25.3.4go get github.com/dgraph-io/dgraph/v25@v25.3.4