THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rrwh-6jrq-wp5v (critical) — Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

[GHSA] GHSA-rrwh-6jrq-wp5v (critical) — Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

highgithub_advisoriesPublished 2026-08-20

GHSA-rrwh-6jrq-wp5v Severity: critical CVE: CVE-2026-54061

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

## Summary

Dgraph Alpha exposes the RPCs used for external snapshot import on the public gRPC port `:9080` without authentication or authorization. As a result, an unauthenticated network client can open `StreamExtSnapshot` and send Badger stream data

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rrwh-6jrq-wp5v