Summary
CVE-2026-44840 is a high-severity DQL (Dgraph Query Language) injection vulnerability in Dgraph, an open-source distributed GraphQL database, affecting all releases prior to version 25.3.4. The flaw allows unauthenticated remote attackers to inject arbitrary DQL query blocks through the checkUserPassword GraphQL query, enabling full exfiltration of database contents without any credentials. A patch is available in version 25.3.4.
Technical details
- Root cause: The
checkUserPasswordGraphQL query builds a DQLcheckpwd()query by interpolating user-supplied password values directly viafmt.Sprintfwith no input escaping or parameterization, classified under CWE-943 (Improper Neutralization of Special Elements in Data Query Logic). - Trigger conditions: An attacker submits a crafted GraphQL
checkUserPasswordrequest containing a double-quote character within the password field; this character breaks out of the DQL string literal context, allowing arbitrary DQL content to be appended. - Attack vector: Exploitable remotely over HTTP on Dgraph’s GraphQL API endpoint (default port 8080), with no authentication, no prior privileges, and no user interaction required.
- Impact: Successful exploitation enables the attacker to append arbitrary DQL query blocks that execute against the database and return results in the HTTP response, achieving full exfiltration of all stored data. Database integrity and availability are not affected.
Affected software
- Dgraph all versions prior to 25.3.4
Severity
CVSS v3.1 Base Score: 7.5 (HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Upgrade Dgraph to version 25.3.4 or later, which resolves the vulnerability by properly escaping or parameterizing user-supplied password values before they are interpolated into DQL queries.
- If immediate patching is not feasible: Restrict network-level access to Dgraph’s HTTP GraphQL API (port 8080) to trusted IP ranges only, and remove any direct public internet exposure of the Dgraph endpoint until the upgrade can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

