What is CVE-2026-73846?
CVE-2026-73846: In CKAN MCP Server versions prior to 0.4.112, the canonicalizeParams function fails to properly escape delimiters like ampersand, equals-sign, and vertical-bar in request parameters, causing cache key collisions. This allows attackers to potentially force different parameter sets to produce the same cache key, leading to data leakage or cache poisoning. Users should update to version 0.4.112 or later.
Azərbaycanca: CVE-2026-73846: CKAN MCP Server-in 0.4.112 versiyasından əvvəlki versiyalarında canonicalizeParams funksiyası sorğu parametrlərini düzgün qaçırmadığı üçün cache key toqquşmalarına səbəb olur. Bu zəiflikdən istifadə edərək təcavüzkar fərqli parametr dəstlərini eyni cache açarına yönəldib potensial məlumat sızmasına şərait yarada bilər. İstifadəçilərə proqramı ən son versiyasına yeniləmələri tövsiyə olunur.
FAQ2
Which function in CKAN MCP Server is affected by the vulnerability CVE-2026-73846?
The vulnerability is caused by the `canonicalizeParams` function, which fails to properly escape delimiters like ampersand, equals-sign, and vertical-bar in request parameters.
To which version should CKAN MCP Server be updated to mitigate CVE-2026-73846?
Users should update to version 0.4.112 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.