Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73976— djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)

Quick assessment

Affected
4TUResearchData djehuty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

djehuty 是由 4TU.ResearchData 开发的一个研究数据仓库系统。在版本 26.3.2 之前,未经身份验证的攻击者可以通过三个不同的参数向搜索/列表查询中注入 SPARQL 代码。由于受影响的查询为只读(SELECT)类型,该漏洞不会向数据存储中写入数据,但允许攻击者执行以下操作: 跨图数据泄露——例如,通过 UNION 操作引入请求原本未授权访问的 RDF 图中的三元组(如存储在 RDF 存储中的草稿、私有或内部数据); 拒绝服务攻击——通过执行高开销或格式错误的查询,占用 SPARQL 后端/

CVSS 7.1 · High EPSS 0.36% · P27

Affected Version Matrix 1

VendorProduct Version RangeStatus
4TUResearchData djehuty < 26.3.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73976

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)
Source: CVE Program / CVE List V5
Vulnerability Description
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
数据查询逻辑中特殊元素的不当中和
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
4TUResearchData djehuty < 26.3.2 -

II. Public POCs for CVE-2026-73976

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73976

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-73976 (1)

Vendor Pages for CVE-2026-73976 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-73976

No comments yet


Leave a comment