๐Ÿ” CVE Alert

CVE-2026-73846

MEDIUM 6.5

CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime a shared cache with a response for a victim's distinct query. This issue is fixed in version 0.4.112.

CWE CWE-345 CWE-436
Vendor ondata
Product ckan-mcp-server
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for ondata ckan-mcp-server

Be the first to know when new medium vulnerabilities affecting ondata ckan-mcp-server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

ondata / ckan-mcp-server
< 0.4.112

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-78x9-fhhx-v2g6 github.com: https://github.com/ondata/ckan-mcp-server/commit/8e1522f9bbfa1f3b21550f17887f60f133e24151 github.com: https://github.com/ondata/ckan-mcp-server/releases/tag/v0.4.112