Djehuty · Djehuty · CVE-2026-73976
**Name of the Vulnerable Software and Affected Versions**
djehuty versions prior to 26.3.2
**Description**
An unauthenticated attacker can perform SPARQL injection in search and listing queries. This occurs through three separate parameters, allowing the attacker to execute read (SELECT) queries. This can lead to cross-graph data exfiltration, such as retrieving triples from graphs not scoped to the request, including private, internal, or draft data stored in the RDF store. Additionally, it can cause a denial of service by executing expensive or malformed queries that exhaust the resources of the SPARQL backend and web workers. SPARQL is a query language designed to retrieve and manipulate data stored in Resource Description Framework (RDF) format.
**Recommendations**
Update to version 26.3.2.