<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:02:19.877279+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-308786</id>
    <title>EUVD-2026-308786</title>
    <updated>2026-10-03T15:02:19.922331+00:00</updated>
    <content>EUVD-2026-308786</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-308786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29090</id>
    <title>fkie_cve-2026-29090</title>
    <updated>2026-10-03T15:02:19.922392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>### Summary</p>
<p>A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticated Rucio user to execute arbitrary SQL against the PostgreSQL metadata database through the DID search endpoint (`GET /dids/&lt;scope&gt;/dids/search`). When the `postgres_meta` metadata plugin is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL strings via Python `.format()`, then passed to `psycopg3`'s `sql.SQL()` which treats the string as trusted SQL syntax.</p>
<p>Depending on the database privileges assigned to the service account, exploitation can expose sensitive tables, modify or delete metadata, access server-side files, or achieve code execution through PostgreSQL features such as COPY ... FROM PROGRAM. This issue affects deployments that explicitly use the postgres_meta metadata plugin. This vulnerability has been fixed in versions 35.8.5, 38.5.5, 39.4.2, and 40.1.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29090"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6j7p-qjhg-9947</id>
    <title>GHSA-6j7p-qjhg-9947 — Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API</title>
    <updated>2026-10-03T15:02:19.922487+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: rucio</p>
<p>### Summary</p>
<p>A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/&lt;scope&gt;/dids/search`). When the external metadata plugin `postgres_meta` is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL statements via Python `str.format`. This enables full database compromise including data exfiltration, data modification, and potential remote code execution via `COPY ... FROM PROGRAM`.</p>
<p>---</p>
<p>### Details</p>
<p>The vulnerability exists in `lib/rucio/core/did_meta_plugins/filter_engine.py` within the `create_postgres_query()` method (lines 408-484). This method builds raw SQL strings via Python `.format()` across 6 distinct injection points:</p>
<p>**filter_engine.py:477** (string equality — default branch):
```python
expression = "{}-&gt;&gt;'{}'  {} '{}'".format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```</p>
<p>**filter_engine.py:442** (wildcard/LIKE branch):
```python
expression = "{}-&gt;&gt;'{}'  LIKE '{}' ".format(jsonb_column, key, value.replace('*', '%'))
```</p>
<p>**filter_engine.py:456** (boolean branch — value unquoted):
```python
expression = "({}-&gt;&gt;'{}'  )::boolean {} {}".format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```</p>
<p>**filter_engine.py:462** (numeric branch — value unquoted):
```python
expression = "({}-&gt;&gt;'{}'  )::float {} {}".format(jsonb_column, key, POSTGRES_OP_MAP[o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6j7p-qjhg-9947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-527</id>
    <title>PYSEC-2026-527 — Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API</title>
    <updated>2026-10-03T15:02:19.922668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: rucio</p>
<p>### Summary</p>
<p>A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/&lt;scope&gt;/dids/search`). When the external metadata plugin `postgres_meta` is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL statements via Python `str.format`. This enables full database compromise including data exfiltration, data modification, and potential remote code execution via `COPY ... FROM PROGRAM`.
 
### Details</p>
<p>*Will follow in two weeks (2025-05-19).*</p>
<p>### Impact</p>
<p>**Vulnerability type:** SQL Injection (CWE-89)</p>
<p>**Who is impacted:**</p>
<p>- Rucio deployments that have explicitly configured the `postgres_meta` metadata plugin.</p>
<p>**What an attacker can do:**</p>
<p>- **Data modification:** PostgreSQL stacked queries enable arbitrary `INSERT`/`UPDATE`/`DELETE` operations.
- **Remote code execution:** Via PostgreSQL's `COPY ... FROM PROGRAM` if the database user has superuser or `pg_execute_server_program` privileges.
- **File system access:** Via `COPY ... TO/FROM '/path'` if filesystem permissions allow.</p>
<p>**Further elevation when the same postgres database and access is used for metadata and for Rucio itself**</p>
<p>- **Full database read access:** Extract any table including `identities` (password hashes and salts), `tokens` (active authentication sessions), `accounts` (user enumeration), `rse_settin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-527"/>
  </entry>
</feed>
