CVE-2026-41328 | dgraph-io dgraph up to 25.3.2 JSON /alter x.PredicateLang pred.Lang data query logic injection
A vulnerability identified as critical has been detected in dgraph-io dgraph up to 25.3.2. Affected is the function x.PredicateLang of the file /alter of the component JSON Handler. The manipulation of the argument pred.Lang leads to improper neutralization of special elements in data query logic.
This vulnerability is documented as CVE-2026-41328. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.