<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:31:56 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-61668 — DIRAC: Pilot code downloaded over unverified HTTPS connection</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-61668</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; DIRACGrid DIRAC&lt;/p&gt;
&lt;p&gt;DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and downloads the reference checksum through the same unvalidated channel. An attacker able to redirect or intercept a grid site&amp;#39;s network traffic through DNS or routing manipulation can substitute both the executable pilot code and its checksum, causing arbitrary code to run in the pilot context with access to pilot proxy credentials. The fixed implementation validates the server certificate through system trust and X509_CERT_DIR or the grid certificate directory. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; DIRACGrid DIRAC&lt;/p&gt;
&lt;p&gt;DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and downloads the reference checksum through the same unvalidated channel. An attacker able to redirect or intercept a grid site&amp;#39;s network traffic through DNS or routing manipulation can substitute both the executable pilot code and its checksum, causing arbitrary code to run in the pilot context with access to pilot proxy credentials. The fixed implementation validates the server certificate through system trust and X509_CERT_DIR or the grid certificate directory. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-61668</guid>
    </item>
    <item>
      <title>GHSA-vg99-gr89-qhw9 — DIRAC: Pilot code downloaded over unverified HTTPS connection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vg99-gr89-qhw9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: DIRAC&lt;/p&gt;
&lt;p&gt;### Summary
The second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers&amp;#39; SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel.&lt;/p&gt;
&lt;p&gt;### Details
The pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python &amp;lt; 2.7.9 behaviour):
https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296&lt;/p&gt;
&lt;p&gt;This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials).&lt;/p&gt;
&lt;p&gt;The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly.&lt;/p&gt;
&lt;p&gt;### Impact
This would require a man-in-the-middle style attack against a grid site&amp;#39;s network (i.e. changing the DNS or routing to redirect the pilot&amp;#39;s connection); this is likely to be difficult which probably limits the potential impact.&lt;/p&gt;
&lt;p&gt;### Patched versions:
https://pypi.org/project/DIRAC/8.0.79/
https://pypi.org/project/DIRAC/9.0.22/
https://pypi.org/project/DIRAC/9.1.10/&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: DIRAC&lt;/p&gt;
&lt;p&gt;### Summary
The second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers&amp;#39; SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel.&lt;/p&gt;
&lt;p&gt;### Details
The pilot wrapper downloads and executes the main second stage pilot script, but the SSL validation on this connection is explicitly disabled (to match old python &amp;lt; 2.7.9 behaviour):
https://github.com/DIRACGrid/DIRAC/blob/integration/src/DIRAC/WorkloadManagementSystem/Utilities/PilotWrapper.py#L292-L296&lt;/p&gt;
&lt;p&gt;This means that the second stage pilot code is not verified in any way and could potentially be altered by a man-in-the-middle attack to execute arbitrary code in the pilot context (i.e. with access to the pilot proxy/credentials).&lt;/p&gt;
&lt;p&gt;The HTTPS connection should be validated against both the system certificates and $X509_CERT_DIR and fail if neither validate correctly.&lt;/p&gt;
&lt;p&gt;### Impact
This would require a man-in-the-middle style attack against a grid site&amp;#39;s network (i.e. changing the DNS or routing to redirect the pilot&amp;#39;s connection); this is likely to be difficult which probably limits the potential impact.&lt;/p&gt;
&lt;p&gt;### Patched versions:
https://pypi.org/project/DIRAC/8.0.79/
https://pypi.org/project/DIRAC/9.0.22/
https://pypi.org/project/DIRAC/9.1.10/&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vg99-gr89-qhw9</guid>
    </item>
  </channel>
</rss>
