CVE-2026-41132Medium▾ SunlitCKAN has no certificate validation on STMP connection
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks.
The vulnerability has been patched in CKAN 2.10.10 and CKAN 2.11.5
ckan >= 2.11.0, < 2.11.5ckan < 2.10.10Upgrade to a patched release:
ckan 2.11.5ckan 2.10.10Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41255Medium· 6.1CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42031HighCKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42032MediumCKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2023-32321Critical· 9.8Ckan remote code execution and private information access via crafted resource ids
CVE-2024-41675Medium· 6.8CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-43371Medium· 4.5Potential access to sensitive URLs via CKAN extensions (SSRF)