Junglewise Threat Intelligence
CVE-2026-34976: GO-2026-5529 - Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
CVE-2026-34976 · Severity: low · CVSS 3.1 · Published 2026-08-11
Technologies: github.com/dgraph-io/dgraph/v25 (Go). Vendors: Go.
Executive brief
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Affected products
- Go github.com/dgraph-io/dgraph/v24
- Go github.com/dgraph-io/dgraph
- Go github.com/dgraph-io/dgraph/v25
- Go github.com/hypermodeinc/dgraph/v24