CVE-2026-73976
⚪ Do wiadomości
Wstrzyknięcie SPARQL w djehuty umożliwia eksfiltrację danych i ataki DoS.
CVSS
0.0
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-10-01 18:17:27 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 18:33:20 UTC |