CVE-2026-61668: DIRAC: Pilot code downloaded over unverified HTTPS connection
The second stage pilot (pilot.tar) is downloaded by the initial wrapper script without any verification of the webservers’ SSL certificate and the contained script is subsequently executed. The checksum is tested, but the reference checksum file is downloaded over the same unvalidated channel.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-61668 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →