CVE-2026-73976
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Summary
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 4TUResearchData | djehuty | < 26.3.2 | affected |
Weaknesses
- CWE-943: CWE-943: Improper Neutralization of Special Elements in Data Query Logic
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/4TUResearchData/djehuty/security/advisories/GHSA-7gp2-rxw9-vw6p
- https://github.com/4TUResearchData/djehuty/releases/tag/v26.3.2
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.