The CVE-2026-53509 vulnerability affects CKAN MCP Server, a tool for querying CKAN open data portals. This Server-Side Request Forgery (SSRF) vulnerability allows remote attackers to make the server connect to local or private addresses and potentially receive response-derived data. The vulnerability is addressed in version 0.4.106. Organizations should be aware of this vulnerability and take steps to mit [truncated]
A vulnerability in CKAN MCP Server, prior to version 0.4.112, allows an attacker to prime a shared cache with a response for a victim's distinct query due to improper serialization of request parameters. This issue is fixed in version 0.4.112. The vulnerability impacts defenders who manage CKAN MCP Server instances, potentially leading to cache poisoning attacks. Defenders should assess exposure and apply [truncated]
A vulnerability in CKAN MCP Server prior to version 0.4.112 allows for spoofed responses due to improper validation of the server_url parameter. This issue is fixed in version 0.4.112. The vulnerability impacts data integrity, and defenders should assess exposure and prioritize upgrading to version 0.4.112 or later. The issue arises from the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s [truncated]
A vulnerability in CKAN MCP Server, a tool for querying CKAN open data portals, allows error paths to reflect raw upstream response bodies and internal exception messages back to the caller. This issue was fixed in version 0.4.112. The vulnerability's impact is limited by the lack of information on widespread exploitation or specific affected systems. Defenders responsible for CKAN MCP Server instances sh [truncated]