Critical severity9.8GHSA Advisory· Published May 13, 2026· Updated May 15, 2026
CVE-2026-42031
CVE-2026-42031
Description
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/advisories/GHSA-h7j7-3rx6-xvcgghsaADVISORY
- github.com/ckan/ckan/security/advisories/GHSA-h7j7-3rx6-xvcgnvdMitigationVendor Advisory
- docs.ckan.org/en/2.10/changelog.htmlghsa
- docs.ckan.org/en/2.11/changelog.htmlghsa
- docs.ckan.org/en/2.11/extensions/plugin-interfaces.htmlghsa
- docs.ckan.org/en/2.11/maintaining/configuration.htmlghsa
- nvd.nist.gov/vuln/detail/CVE-2026-42031ghsa
News mentions
0No linked articles in our index yet.