Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2. | |
| Title | djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`) | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-01T17:58:15.800Z
Reserved: 2026-08-13T21:42:04.045Z
Link: CVE-2026-73976
Updated: 2026-10-01T17:56:06.607Z
Status : Received
Published: 2026-10-01T18:17:27.550
Modified: 2026-10-01T18:17:27.550
Link: CVE-2026-73976
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:15:12Z