Medium severity6.5NVD Advisory· Published Aug 14, 2026· Updated Sep 18, 2026
CVE-2026-73846
CVE-2026-73846
Description
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime a shared cache with a response for a victim's distinct query. This issue is fixed in version 0.4.112.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@aborruso/ckan-mcp-servernpm | < 0.4.112 | 0.4.112 |
Affected products
1- Range: <0.4.112
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-78x9-fhhx-v2g6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-73846ghsaADVISORY
- github.com/ondata/ckan-mcp-server/commit/8e1522f9bbfa1f3b21550f17887f60f133e24151nvdWEB
- github.com/ondata/ckan-mcp-server/releases/tag/v0.4.112nvdWEB
- github.com/ondata/ckan-mcp-server/security/advisories/GHSA-78x9-fhhx-v2g6nvdWEB
News mentions
0No linked articles in our index yet.