Critical severity9.1NVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
CVE-2026-54061
CVE-2026-54061
Description
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port :9080 without authentication or authorization. As a result, an unauthenticated network client can open StreamExtSnapshot and send Badger stream data to the target group’s store. In addition, the receiver calls Prepare() before processing the stream. This operation deletes and replaces the existing DB data. Version 25.3.5 patches the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/dgraph-io/dgraph/v25Go | < 25.3.5 | 25.3.5 |
Affected products
2- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.