CVE-2026-73846Medium· 6.5▾ SunlitCKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing differen…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
0.1% → 0.2%
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime a shared cache with a response for a victim's distinct query. This issue is fixed in version 0.4.112.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@aborruso/ckan-mcp-server < 0.4.112Patched in:
@aborruso/ckan-mcp-server 0.4.112Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73845Medium· 5.3CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-73844Low· 3.7CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-53509Medium· 5.7CKAN MCP Server is a tool for querying CKAN open data portals
CVE-2026-56669High· 7.5elysia has Inefficient Algorithmic Complexity and Interpretation Conflict
CVE-2026-86038High· 7.5libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack