<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – ArangoDB (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/arangodb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/arangodb-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – ArangoDB (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-36084 – cruddl is software for creating a GraphQL API for a database, using the GraphQL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36084</guid>
    <pubDate>Thu, 08 Sep 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36084</strong></p>
  <p>cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB. Schemas that do not use `@flexSearchFullt…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25940 – In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25940</guid>
    <pubDate>Tue, 16 Nov 2021 10:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25940</strong></p>
  <p>In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25940">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
