CVE-2026-73844
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and intern
CVSS
3.7
Bajo
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 14 ago 2026 · Última mod.: 14 ago 2026 · CWE-209 · CWE-210
Sin historial EPSS suficiente todavía.
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments). This vulnerability is fixed in 0.4.112.