Junglewise Threat Intelligence

CVE-2026-41492: GO-2026-5675 - Unauthenticated admin token disclosure via /debug/vars in github.com/dgraph-io/dgraph

CVE-2026-41492 · Severity: low · CVSS 3.1 · Published 2026-07-23

Technologies: github.com/dgraph-io/dgraph/v24 (Go), github.com/dgraph-io/dgraph (Go), github.com/hypermodeinc/dgraph/v24 (Go), github.com/dgraph-io/dgraph/v25 (Go). Vendors: Go.

Executive brief

Unauthenticated admin token disclosure via /debug/vars in github.com/dgraph-io/dgraph

Affected products

  • Go github.com/dgraph-io/dgraph/v24
  • Go github.com/dgraph-io/dgraph
  • Go github.com/hypermodeinc/dgraph/v24
  • Go github.com/dgraph-io/dgraph/v25

Related threats