Junglewise Threat Intelligence

CVE-2026-63637: Dgraph DQL injection via unvalidated regexp filter

CVE-2026-63637 · Severity: high · CVSS 8.6 · Published 2026-08-06

Technologies: Dgraph.

Executive brief

Dgraph is an open-source distributed GraphQL database used to store and query complex data. A vulnerability in its query rewriter allows attackers to inject arbitrary database commands through GraphQL queries and mutations that use regexp filters, enabling unauthorized data disclosure or bulk data modification without authentication. This could expose sensitive application data or allow attackers to delete or modify records en masse.

Technical details

The vulnerability is a DQL (Dgraph Query Language) injection in the maybeQuoteArg function in graphql/resolve/query_rewriter.go. The function explicitly skips sanitization for regexp filter arguments, passing user input directly into generated DQL without validation or escaping. An attacker sends a GraphQL query or mutation with a crafted regexp filter value that closes the regex literal, closes the function call, and injects arbitrary DQL operators (OR, has, eq, uid), which are then tokenized and executed as valid DQL syntax. Exploitation requires only network access and a schema with at least one @search(by: [regexp]) field; no authentication is required for queries, and mutations require only basic user-level auth. The attack bypasses intended query filters to retrieve all data or expands mutation/deletion targets. The fix validates regexp input format or uses DQL variable bindings, available in version 25.3.8.

Affected products

  • Dgraph Dgraph prior to 25.3.8

Timeline

  • 2026-07-17: disclosed: GitHub Security Advisory GHSA-33p8-wc97-5qcj published
  • 2026-08-06: patched: CVE-2026-63637 published; fix available in v25.3.8

References