CVE-2026-73846: Ondata Ckan-Mcp-Server

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime a shared cache with a response for a victim's distinct query. This issue is fixed in version 0.4.112.

Affected products

  • Ondata Ckan-Mcp-Server: before 0.4.112 (fixed in 0.4.112)

Published 2026-08-14. Last modified 2026-09-18.