rucio
Rucio - Scientific Data Management
Activity
- Latest release
- 6d ago
- Total releases
- 479
- Cadence
- ~6 days
- Last 12 months
- 46
Reach
- Stars
- 320
Details
- License
- Apache-2.0
- First release
- May 10, 2016
| Version | Released | |
|---|---|---|
41.2.2
patch
| ||
38.6.2
patch
| ||
41.2.1
patch
| ||
35.9.2
patch
| ||
41.2.0
minor
| ||
35.9.1.post2
pre
| ||
35.9.1.post1
pre
| ||
35.9.1
patch
| ||
40.4.2
patch
| ||
38.6.1
patch
| ||
41.1.1
patch
| ||
41.1.0
minor
| ||
41.0.0
major
| ||
38.6.0
minor
| ||
35.9.0
minor
| ||
41.0.0rc1
pre
| ||
40.4.1
patch
| ||
40.4.0
minor
| ||
40.3.0
minor
| ||
40.2.0
minor
| ||
40.1.2
patch
| ||
35.8.5
patch
| ||
38.5.5
patch
| ||
39.4.2
patch
| ||
40.1.1
patch
| ||
40.0.0
major
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
40.1.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
40.0.0rc1
pre
| ||
39.4.1
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
35.8.4
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.4.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
35.8.3
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.5.4
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.3.1
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.5.3
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.3.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.5.2
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.2.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.1.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
35.8.2
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.0.0
major
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
39.0.0rc2
pre
| ||
39.0.0rc1
pre
| ||
38.5.1
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.5.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.4.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.3.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.2.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
35.8.1
patch
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev | ||
38.1.0
minor
2 CVEs
CVE-2026-29080
PYSEC-2026-528
GHSA-vjr5-c9qv-hgm3
Jun 29, 2026
Rucio has SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in the Oracle path of DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.27.0
1.27.0.post1
1.27.1
1.27.10
1.27.11
1.27.12
1.27.2
1.27.3
1.27.4
1.27.4.post1
1.27.5
1.27.7
+ 170 more Show less
1.27.9
1.28.0
1.28.0rc1
1.28.0rc2
1.28.1
1.28.2
1.28.3
1.28.4
1.28.5
1.28.6
1.28.7
1.29.0
1.29.0rc1
1.29.0rc2
1.29.1
1.29.10
1.29.11
1.29.12
1.29.13
1.29.14
1.29.15
1.29.16
1.29.17
1.29.18
1.29.19
1.29.2
1.29.2.post1
1.29.2.post2
1.29.3
1.29.3.post1
1.29.4
1.29.5
1.29.6
1.29.7
1.29.7.post1
1.29.8
1.29.9
1.30.0
1.30.0rc1
1.30.0rc2
1.30.0rc3
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-29090
PYSEC-2026-527
GHSA-6j7p-qjhg-9947
Jun 29, 2026
Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API
Critical
Network
Low
Low
None
SummaryA SQL injection vulnerability in DetailsWill follow in two weeks (2025-05-19). ImpactVulnerability type: SQL Injection (CWE-89) Who is impacted:
What an attacker can do:
Further elevation when the same postgres database and access is used for metadata and for Rucio itself
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The Affected versions
1.30.0
1.30.1
1.30.2
1.30.3
1.30.4
1.30.5
1.30.6
1.30.7
1.30.8
1.31.0
1.31.0rc1
1.31.0rc2
+ 118 more Show less
1.31.0rc3
1.31.1
1.31.2
1.31.3
1.31.4
1.31.5
1.31.6
1.31.7
32.0.0
32.0.0rc1
32.0.0rc2
32.1.0
32.2.0
32.3.0
32.3.1
32.4.0
32.5.0
32.5.0.post1
32.5.1
32.6.0
32.6.0.post1
32.7.0
32.8.0
32.8.1
32.8.2
32.8.3
32.8.4
32.8.5
32.8.6
33.0.0
33.0.0rc1
33.0.0rc2
33.0.0rc3
33.1.0
33.2.0
33.2.1
33.3.0
33.4.0
33.4.0.post1
33.5.0
33.6.0
33.6.1
34.0.0
34.0.0rc1
34.0.0rc2
34.1.0
34.2.0
34.3.0
34.4.0
34.4.1
34.4.2
34.4.3
34.5.0
34.6.0
35.0.0
35.0.0rc1
35.0.0rc2
35.0.1
35.1.0
35.1.1
35.2.0
35.2.1
35.3.0
35.4.0
35.4.1
35.5.0
35.6.0
35.6.1
35.7.0
35.8.0
35.8.1
35.8.2
35.8.3
35.8.4
36.0.0
36.0.0.post1
36.0.0.post2
36.1.0
36.2.0
36.3.0
36.4.0
36.5.0
37.0.0
37.0.0rc1
37.0.0rc2
37.0.0rc3
37.0.0rc4
37.1.0
37.1.0.post1
37.2.0
37.3.0
37.4.0
37.5.0
37.6.0
37.7.0
37.7.1
38.0.0
38.0.0rc1
38.0.0rc2
38.0.0rc3
38.1.0
38.2.0
38.3.0
38.4.0
38.5.0
38.5.1
38.5.2
38.5.3
38.5.4
39.0.0
39.1.0
39.2.0
39.3.0
39.3.1
39.4.0
39.4.1
40.0.0
40.1.0
Fixed in
35.8.5
38.5.5
39.4.2
40.1.1
References Updated Jul 02, 2026 · Source: OSV.dev |