{"id":"GO-2026-5274","summary":"Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph","details":"The /debug/pprof/cmdline endpoint in Dgraph Alpha discloses the command-line arguments used to start the process, which may include the administrator's authentication token if provided via the --auth_token flag. This allows an unauthenticated remote attacker to obtain the token and gain full administrative access to the Dgraph cluster.","aliases":["CVE-2026-40173","GHSA-95mq-xwj4-r47p"],"modified":"2026-08-11T20:33:01.945728099Z","published":"2026-08-11T20:19:48Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5274","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/dgraph-io/dgraph/security/advisories/GHSA-95mq-xwj4-r47p"},{"type":"WEB","url":"https://github.com/dgraph-io/dgraph/releases/tag/v25.3.2"}],"affected":[{"package":{"name":"github.com/dgraph-io/dgraph","ecosystem":"Go","purl":"pkg:golang/github.com/dgraph-io/dgraph"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/dgraph-io/dgraph"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5274.json"}},{"package":{"name":"github.com/dgraph-io/dgraph/v25","ecosystem":"Go","purl":"pkg:golang/github.com/dgraph-io/dgraph/v25"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"25.3.2"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/dgraph-io/dgraph/v25"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5274.json"}},{"package":{"name":"github.com/hypermodeinc/dgraph/v24","ecosystem":"Go","purl":"pkg:golang/github.com/hypermodeinc/dgraph/v24"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"24.1.9"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/hypermodeinc/dgraph/v24"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5274.json"}}],"schema_version":"1.9.0"}