CVE-2026-73976: djehuty: Unauthenticated SPARQL injection in the search API (`order`, `operator`, `key`)

Published Oct 1, 2026
·
Updated

djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows: Cross-graph data exfiltration — e.g. UNION-ing in triples from graphs the request was never scoped to (drafts/private/internal data held in the RDF store); denial of service — expensive or malformed queries that tie up the SPARQL backend / web workers. No account or user interaction is required. This issue has been patched in version 26.3.2.

Affected Software

1 affected component
4TU.ResearchData djehuty<26.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade djehuty to a version that resolves this vulnerability.

    Fixed in 26.3.2

Event History

Oct 1, 2026
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed?

djehuty deployments running versions before 26.3.2 are affected if their search or listing API is reachable by an unauthenticated attacker. No account or user interaction is required.

2

What can an attacker access or do through this issue?

An attacker can inject SPARQL through the order, operator, or key parameters to read data across RDF graphs outside the request’s intended scope, including potentially draft, private, or internal data. They can also submit expensive or malformed queries that consume SPARQL backend or web-worker resources.

3

Can this vulnerability modify repository data?

The affected queries are SELECT queries, so the described issue does not write to the RDF store. Its stated impacts are data exfiltration and denial of service.

4

What is the available remediation?

Upgrade djehuty to version 26.3.2, which contains the patch. The provided information does not describe an alternative mitigation for systems that cannot yet be upgraded.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203