VDB
Sign up
—

GO-2026-5837

DQL injection via checkUserPassword GraphQL query in github.com/dgraph-io/dgraph

Quick fix

GO-2026-5837 — github.com/dgraph-io/dgraph/v25: upgrade to the fixed version with the command below.

go get github.com/dgraph-io/dgraph/v25@v25.3.4

Details

The checkUserPassword GraphQL query in Dgraph is vulnerable to Dgraph Query Language (DQL) injection. User-supplied password values are interpolated directly into a DQL checkpwd query without escaping or parameterization. An attacker can inject a password containing a double-quote character to break out of the DQL string literal and append arbitrary DQL query blocks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dgraph-io/dgraph
Introduced in: 0

No fixed version published yet for github.com/dgraph-io/dgraph (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/hypermodeinc/dgraph/v24
Introduced in: 0

No fixed version published yet for github.com/hypermodeinc/dgraph/v24 (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/dgraph-io/dgraph/v25
Introduced in: 0Fixed in: 25.3.4
Fixgo get github.com/dgraph-io/dgraph/v25@v25.3.4

References