Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3464
  • PyPI/dirac
DIRAC: Pilot code downloaded over unverified HTTPS connection 23 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3463
  • PyPI/dirac
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval 23 Jul
  • Fix available
  • Severity - 9.9 (Critical)
PYSEC-2026-3462
  • PyPI/dirac
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input 23 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-7xw9-549r-8jrc
  • PyPI/dirac
DIRAC: SQL injection and lack of access control in PilotManager service 13 Jul
  • Fix available
  • Severity - 8.5 (High)
GHSA-vg99-gr89-qhw9
  • PyPI/dirac
DIRAC: Pilot code downloaded over unverified HTTPS connection 13 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-m4m7-4cw8-62j6
  • PyPI/dirac
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval 13 Jul
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-9jpv-c7p4-997x
  • PyPI/dirac
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input 13 Jul
  • Fix available
  • Severity - 9.9 (Critical)
PYSEC-2026-1295
  • PyPI/dirac
DIRAC: Unauthorized users can read proxy contents during generation 07 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-v6f3-gh5h-mqwx
  • PyPI/dirac
DIRAC: Unauthorized users can read proxy contents during generation 09 Apr 2024
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2024-125
  • PyPI/dirac
  • github.com/DIRACGrid/DIRAC
See record for full details 09 Feb 2024
  • Fix available
  • Severity - 7.5 (High)
GHSA-59qj-jcjv-662j
  • PyPI/dirac
DIRAC's TokenManager does not check permissions on cached tokens 08 Feb 2024
  • Fix available
  • Severity - 9.1 (Critical)