{"id":"CVE-2026-73976","summary":"djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)","details":"djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.","aliases":["GHSA-7gp2-rxw9-vw6p"],"modified":"2026-10-02T03:47:47.603539409Z","published":"2026-10-01T17:08:11.924Z","database_specific":{"cwe_ids":["CWE-943"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73976.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2"},{"type":"ADVISORY","url":"https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73976.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73976"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/4turesearchdata/djehuty","events":[{"introduced":"0"},{"fixed":"f40fe003febc9c164798bf2f6330cabd7896a662"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"26.3.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v26.3.1","v26.3","v25.6","v25.5","v25.4","v25.3","v25.2","v25.1","v24.12","v24.11","v24.10.1","v24.10","v24.9","v24.8","v24.7","v24.6","v24.5","v24.4","v24.3","v24.2","v24.1","production","user-testing-4","user-testing-3","user-testing-2","user-testing-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73976.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}