CVE-2026-73976
djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)
djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration โ e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service โ expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.
| CWE | CWE-943 |
| Vendor | 4turesearchdata |
| Product | djehuty |
| Published | Oct 1, 2026 |
| Last Updated | Oct 1, 2026 |
Get instant alerts for 4turesearchdata djehuty
Be the first to know when new unknown vulnerabilities affecting 4turesearchdata djehuty are published โ delivered to Slack, Telegram or Discord.