CVE-2026-41327 | dgraph-io dgraph up to 25.3.2 DQL Parser /mutate?commitNow=true cond data query logic injection
A vulnerability marked as critical has been reported in dgraph-io dgraph up to 25.3.2. The impacted element is an unknown function of the file /mutate?commitNow=true of the component DQL Parser. The manipulation of the argument cond leads to improper neutralization of special elements in data query logic.
This vulnerability is documented as CVE-2026-41327. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.