DIRAC
DIRAC Grid
Activity
- Latest release
- 3h ago
- Total releases
- 354
- Cadence
- ~4 days
- Last 12 months
- 51
Reach
- Stars
- 126
Details
- License
- unknown
- First release
- Jan 20, 2021
| Version | Released | |
|---|---|---|
9.0.25
patch
| ||
9.1.18
patch
| ||
8.0.83
patch
| ||
9.1.17
patch
| ||
9.1.16
patch
| ||
9.1.15
patch
| ||
9.1.14
patch
| ||
8.0.82
patch
| ||
9.0.24
patch
| ||
9.1.13
patch
| ||
9.0.23
patch
| ||
8.0.81
patch
| ||
9.1.12
patch
| ||
9.1.11
patch
| ||
9.1.10
patch
| ||
9.0.22
patch
| ||
8.0.80
patch
| ||
8.0.79
patch
| ||
9.0.21
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.9
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.8
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.7
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.6
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.5
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.4
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.3
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.2
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.1
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.0
minor
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.20
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.19
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.0.78
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.18
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.17
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.16
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.15
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.14
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.0a70
pre
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.13
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.12
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.11
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.10
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.9
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.8
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.7
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.0.77
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.6
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.5
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.4
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.2
patch
4 CVEs
CVE-2026-61668
PYSEC-2026-3464
GHSA-vg99-gr89-qhw9
Jul 23, 2026
DIRAC: Pilot code downloaded over unverified HTTPS connection
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
SummaryThe second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers' SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel. DetailsThe pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python < 2.7.9 behaviour): https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296 This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials). The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly. ImpactThis would require a man-in-the-middle style attack against a grid site's network (i.e. changing the DNS or routing to redirect the pilot's connection); this is likely to be difficult which probably limits the potential impact. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-61667
PYSEC-2026-3463
GHSA-m4m7-4cw8-62j6
Jul 23, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryThe FileCatalog DatasetManager runs a query on the database and passes the result to eval. The SQL query contains an injection vulnerability which allows an authenticated user to control the parameter returned to the eval resulting in remote code execution. DetailsThe FileCatalog checkDataset function passes its datasets argument directly to the backend DB handler: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/Service/FileCatalogHandler.py#L591-L593 Which in turn passes it to the __checkDataset function: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L390 This uses an f-string to create a query without escaping, resulting in an SQL injection: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L400-L402 The result (which is user controllable due to the SQL injection) is passed into eval almost immediately on return, leading to code execution: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/DataManagementSystem/DB/FileCatalogComponents/DatasetManager/DatasetManager.py#L409 There are other functions in the same file which use a similar pattern and would likely be exploitable in a similar way. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
CVE-2026-45579
PYSEC-2026-3462
GHSA-9jpv-c7p4-997x
Jul 23, 2026
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
SummaryAn remote code execution vulnerability exists in RequestManager due to the use of eval on untrusted input that allows any authenticated user to run code/commands on the DIRAC server as the system user running the DIRAC services. DetailsThe export_getRequestCountersWeb function is callable by any authenticated user and just passes its parameters directly to the database instance: https://github.com/DIRACGrid/DIRAC/blob/f7e0a3ac153315030fb3520e8ca747f013758967/src/DIRAC/RequestManagementSystem/Service/ReqManagerHandler.py#L270 If the groupingAttribute string is unrecognised, By passing in a dunder string that is applicable to the Request object, it's possible to work back up to functions in the os module and trigger them to be called in the server context. There are other uses of eval in ReqManager/RequestDB which may be equally accessible. ImpactThis allows any authenticated user to run commands on the server, which allows a full compromise of the DIRAC system (they can read the local dirac.cfg, get database passwords and export all stored proxies and tokens). If local logging is used, they can also remove evidence of the exploit from the log (it leaves an exception printout in the RequestManager log when used). Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 23, 2026 · Source: OSV.dev
GHSA-7xw9-549r-8jrc
Jul 13, 2026
DIRAC: SQL injection and lack of access control in PilotManager service
8.5
/ 10
High
Network
Low
Low
None
Changed
Low
High
None
DetailsA number of the functions in PilotManager pass parameters directly through to the database layer, which then does not do any escaping on the parameters. For example setPilotStatus: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/Service/PilotManagerHandler.py#L343-L349 https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/DB/PilotAgentsDB.py#L117 This won't accept multiple statements separated by a semicolon, but a carefully crafted set of parameters containing SQL escapes would likely be able to change or return other database entries. Further to this, the PilotManager access control is only set to "authenticated"; this allows these functions to be called by any user. This allows any user to manage (e.g. delete, read output of) any pilot pilot job: https://github.com/DIRACGrid/DIRAC/blob/1738e7c6d2f31d26f1364255d9d2e87b4896c922/src/DIRAC/WorkloadManagementSystem/ConfigTemplate.cfg#L111-L118 This is fixed by changing the SQL statements to use proper parameter substitution and providing a suitable set of access rules for the exported pilot management functions. Patched versions:https://pypi.org/project/DIRAC/8.0.79/ https://pypi.org/project/DIRAC/9.0.22/ https://pypi.org/project/DIRAC/9.1.10/ Affected versions
7.2.0
7.2.0a32
7.2.0a33
7.2.0a34
7.2.0a35
7.2.0a36
7.2.0a38
7.2.0a39
7.2.1
7.2.10
7.2.12
7.2.13
+ 324 more Show less
7.2.14
7.2.15
7.2.16
7.2.19
7.2.2
7.2.20
7.2.21
7.2.22
7.2.23
7.2.24
7.2.25
7.2.26
7.2.27
7.2.28
7.2.3
7.2.30
7.2.31
7.2.32
7.2.33
7.2.34
7.2.35
7.2.36
7.2.37
7.2.38
7.2.39
7.2.4
7.2.40
7.2.41
7.2.42
7.2.43
7.2.44
7.2.45
7.2.46
7.2.47
7.2.48
7.2.49
7.2.5
7.2.50
7.2.51
7.2.52
7.2.6
7.2.7
7.2.8
7.2.9
7.2a29
7.3.0a10
7.3.0a11
7.3.0a13
7.3.0a14
7.3.0a15
7.3.0a16
7.3.0a17
7.3.0a18
7.3.0a19
7.3.0a2
7.3.0a20
7.3.0a21
7.3.0a22
7.3.0a23
7.3.0a24
7.3.0a3
7.3.0a4
7.3.0a5
7.3.0a6
7.3.0a7
7.3.0a8
7.3.0a9
7.3.1
7.3.10
7.3.11
7.3.12
7.3.13
7.3.14
7.3.15
7.3.16
7.3.17
7.3.18
7.3.19
7.3.2
7.3.20
7.3.21
7.3.22
7.3.23
7.3.24
7.3.26
7.3.27
7.3.28
7.3.29
7.3.3
7.3.30
7.3.31
7.3.32
7.3.33
7.3.34
7.3.35
7.3.36
7.3.37
7.3.38
7.3.4
7.3.5
7.3.6
7.3.7
7.3.8
7.3.9
7.4.0a1
8.0.0
8.0.0a1
8.0.0a10
8.0.0a11
8.0.0a12
8.0.0a13
8.0.0a14
8.0.0a15
8.0.0a16
8.0.0a17
8.0.0a18
8.0.0a19
8.0.0a20
8.0.0a21
8.0.0a22
8.0.0a23
8.0.0a24
8.0.0a25
8.0.0a26
8.0.0a27
8.0.0a28
8.0.0a29
8.0.0a5
8.0.0a6
8.0.0a7
8.0.0a8
8.0.0a9
8.0.1
8.0.10
8.0.11
8.0.12
8.0.13
8.0.14
8.0.15
8.0.16
8.0.17
8.0.18
8.0.19
8.0.2
8.0.20
8.0.21
8.0.22
8.0.23
8.0.24
8.0.25
8.0.26
8.0.27
8.0.28
8.0.29
8.0.3
8.0.30
8.0.31
8.0.32
8.0.33
8.0.34
8.0.35
8.0.36
8.0.37
8.0.38
8.0.39
8.0.4
8.0.40
8.0.41
8.0.42
8.0.43
8.0.44
8.0.45
8.0.46
8.0.47
8.0.48
8.0.49
8.0.5
8.0.50
8.0.51
8.0.52
8.0.53
8.0.54
8.0.55
8.0.56
8.0.58
8.0.59
8.0.6
8.0.60
8.0.61
8.0.62
8.0.63
8.0.64
8.0.65
8.0.66
8.0.67
8.0.68
8.0.69
8.0.7
8.0.70
8.0.71
8.0.72
8.0.73
8.0.74
8.0.75
8.0.76
8.0.77
8.0.78
8.0.8
8.0.9
8.1.0a1
8.1.0a10
8.1.0a11
8.1.0a12
8.1.0a13
8.1.0a14
8.1.0a15
8.1.0a16
8.1.0a17
8.1.0a18
8.1.0a19
8.1.0a2
8.1.0a20
8.1.0a21
8.1.0a22
8.1.0a23
8.1.0a3
8.1.0a4
8.1.0a5
8.1.0a6
8.1.0a7
8.1.0a8
8.1.0a9
9.0.0
9.0.0a1
9.0.0a10
9.0.0a11
9.0.0a12
9.0.0a13
9.0.0a16
9.0.0a17
9.0.0a18
9.0.0a19
9.0.0a2
9.0.0a20
9.0.0a21
9.0.0a22
9.0.0a23
9.0.0a24
9.0.0a25
9.0.0a26
9.0.0a27
9.0.0a28
9.0.0a29
9.0.0a3
9.0.0a30
9.0.0a31
9.0.0a35
9.0.0a36
9.0.0a37
9.0.0a38
9.0.0a39
9.0.0a4
9.0.0a40
9.0.0a41
9.0.0a42
9.0.0a43
9.0.0a44
9.0.0a45
9.0.0a46
9.0.0a47
9.0.0a48
9.0.0a49
9.0.0a5
9.0.0a50
9.0.0a51
9.0.0a52
9.0.0a53
9.0.0a54
9.0.0a55
9.0.0a56
9.0.0a57
9.0.0a58
9.0.0a59
9.0.0a6
9.0.0a60
9.0.0a61
9.0.0a62
9.0.0a63
9.0.0a64
9.0.0a66
9.0.0a67
9.0.0a68
9.0.0a69
9.0.0a70
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.15
9.0.16
9.0.17
9.0.18
9.0.19
9.0.2
9.0.20
9.0.21
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.2
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
Fixed in
8.0.79
9.0.22
9.1.10
References Updated Jul 13, 2026 · Source: OSV.dev |