<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 23:36:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-29090 — Rucio SQL injection in postgres_meta DID search path compromises PostgreSQL metadata database</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-29090</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; rucio&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticated Rucio user to execute arbitrary SQL against the PostgreSQL metadata database through the DID search endpoint (`GET /dids/&amp;lt;scope&amp;gt;/dids/search`). When the `postgres_meta` metadata plugin is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL strings via Python `.format()`, then passed to `psycopg3`&amp;#39;s `sql.SQL()` which treats the string as trusted SQL syntax.&lt;/p&gt;
&lt;p&gt;Depending on the database privileges assigned to the service account, exploitation can expose sensitive tables, modify or delete metadata, access server-side files, or achieve code execution through PostgreSQL features such as COPY ... FROM PROGRAM. This issue affects deployments that explicitly use the postgres_meta metadata plugin. This vulnerability has been fixed in versions 35.8.5, 38.5.5, 39.4.2, and 40.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; rucio&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticated Rucio user to execute arbitrary SQL against the PostgreSQL metadata database through the DID search endpoint (`GET /dids/&amp;lt;scope&amp;gt;/dids/search`). When the `postgres_meta` metadata plugin is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL strings via Python `.format()`, then passed to `psycopg3`&amp;#39;s `sql.SQL()` which treats the string as trusted SQL syntax.&lt;/p&gt;
&lt;p&gt;Depending on the database privileges assigned to the service account, exploitation can expose sensitive tables, modify or delete metadata, access server-side files, or achieve code execution through PostgreSQL features such as COPY ... FROM PROGRAM. This issue affects deployments that explicitly use the postgres_meta metadata plugin. This vulnerability has been fixed in versions 35.8.5, 38.5.5, 39.4.2, and 40.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-29090</guid>
    </item>
    <item>
      <title>GHSA-6j7p-qjhg-9947 — Rucio has SQL Injection in FilterEngine PostgreSQL Query Builder via DID Search API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6j7p-qjhg-9947</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: rucio&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/&amp;lt;scope&amp;gt;/dids/search`). When the external metadata plugin `postgres_meta` is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL statements via Python `str.format`. This enables full database compromise including data exfiltration, data modification, and potential remote code execution via `COPY ... FROM PROGRAM`.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `lib/rucio/core/did_meta_plugins/filter_engine.py` within the `create_postgres_query()` method (lines 408-484). This method builds raw SQL strings via Python `.format()` across 6 distinct injection points:&lt;/p&gt;
&lt;p&gt;**filter_engine.py:477** (string equality — default branch):
```python
expression = &amp;#34;{}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  {} &amp;#39;{}&amp;#39;&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:442** (wildcard/LIKE branch):
```python
expression = &amp;#34;{}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  LIKE &amp;#39;{}&amp;#39; &amp;#34;.format(jsonb_column, key, value.replace(&amp;#39;*&amp;#39;, &amp;#39;%&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:456** (boolean branch — value unquoted):
```python
expression = &amp;#34;({}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  )::boolean {} {}&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:462** (numeric branch — value unquoted):
```python
expression = &amp;#34;({}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  )::float {} {}&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: rucio&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A SQL injection vulnerability in `FilterEngine.create_postgres_query` allows any authenticated Rucio user to execute arbitrary SQL against the configured PostgreSQL metadata database through the DID search endpoint (`GET /dids/&amp;lt;scope&amp;gt;/dids/search`). When the external metadata plugin `postgres_meta` is configured, attacker-controlled filter keys and values are interpolated directly into raw SQL statements via Python `str.format`. This enables full database compromise including data exfiltration, data modification, and potential remote code execution via `COPY ... FROM PROGRAM`.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability exists in `lib/rucio/core/did_meta_plugins/filter_engine.py` within the `create_postgres_query()` method (lines 408-484). This method builds raw SQL strings via Python `.format()` across 6 distinct injection points:&lt;/p&gt;
&lt;p&gt;**filter_engine.py:477** (string equality — default branch):
```python
expression = &amp;#34;{}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  {} &amp;#39;{}&amp;#39;&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:442** (wildcard/LIKE branch):
```python
expression = &amp;#34;{}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  LIKE &amp;#39;{}&amp;#39; &amp;#34;.format(jsonb_column, key, value.replace(&amp;#39;*&amp;#39;, &amp;#39;%&amp;#39;))
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:456** (boolean branch — value unquoted):
```python
expression = &amp;#34;({}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  )::boolean {} {}&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[oper], value)
```&lt;/p&gt;
&lt;p&gt;**filter_engine.py:462** (numeric branch — value unquoted):
```python
expression = &amp;#34;({}-&amp;gt;&amp;gt;&amp;#39;{}&amp;#39;  )::float {} {}&amp;#34;.format(jsonb_column, key, POSTGRES_OP_MAP[o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6j7p-qjhg-9947</guid>
    </item>
  </channel>
</rss>
