Vulnerability  ·  2026-08-15

CKAN MCP Server — cache-key collision and MQA quality-check hostname bypass (2 CVEs)

VulnerabilityMedium impactGlobalCVE-2026-73846
NVD published CVE-2026-73846 (CVSS 6.5, Medium) and CVE-2026-73845 (CVSS 5.3, Medium) on 2026-08-14, describing a cache-key collision vulnerability and a hostname-validation bypass in CKAN MCP Server's data-quality checking tools.
Low blast radius — a single niche open-data MCP integration — but represents the broader pattern of insufficiently validated hostname/URL checks in MCP tool implementations that can be chained toward SSRF or data leakage.
CVE-2026-73846: canonicalizeParams serializes request parameters with unescaped delimiters allowing cache-key collisions and cross-request cache poisoning; CVE-2026-73845: isValidMqaServer uses a prefix-only regex for dati.gov.it validation, allowing suffix-hostname bypass for SSRF-adjacent access
CKAN MCP Server < 0.4.112
Upgrade CKAN MCP Server to 0.4.112 or later
CKAN MCP Server commit
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →