CVE-2023-50248Medium· 4.5▾ SunlitOut of memory error when submitting the dataset form with a specially-crafted field
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
0.6% → 0.6%
Last analysed / modified upstream
When submitting a POST request to the /dataset/new endpoint (including either the auth cookie or the Authorization header) with a specially-crafted field, an attacker can create an out-of-memory error in the hosting server.
To trigger this error the user needs to have permissions to create or edit datasets.
This vulnerability has been patched in CKAN 2.10.3 and 2.9.10
ckan >= 2.0, < 2.9.10ckan >= 2.10.0, < 2.10.3Upgrade to a patched release:
ckan 2.9.10ckan 2.10.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
CVE-2026-41132MediumCKAN has no certificate validation on STMP connection
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42031HighCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin