DIRAC vulnerabilities
CVEs whose affected-version data names the DIRAC package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-61667Critical· 9.9DIRAC is an interware, meaning a software framework for distributed computing
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled data…
CVE-2026-61668High· 8.1DIRAC is an interware, meaning a software framework for distributed computing
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to dow…
CVE-2026-45579Critical· 9.9DIRAC is an interware, meaning a software framework for distributed computing
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authent…
GHSA-7xw9-549r-8jrcHigh· 8.5DIRAC: SQL injection and lack of access control in PilotManager service
DIRAC: SQL injection and lack of access control in PilotManager service
CVE-2024-29905High· 8.1DIRAC: Unauthorized users can read proxy contents during generation
DIRAC: Unauthorized users can read proxy contents during generation
CVE-2024-24825Critical· 9.1DIRAC's TokenManager does not check permissions on cached tokens
DIRAC's TokenManager does not check permissions on cached tokens