CVE-2026-73844CWE-209CWE-210

CVE-2026-73844

Low · published August 14, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
12.8
In the wild
Unconfirmed
What it is

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments). This vulnerability is fixed in 0.4.112.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00223 · 12.8th percentile
Weaknesses
CWE-209 · Generation of Error Message Containing Sensitive Information; CWE-210 · Self-generated Error Message Containing Sensitive Information
Published
2026-08-14T21:20Z
References (3)
EPSS history
Timeline
  • 14 AUG 16:41Z
    CKAN MCP Server: Information disclosure via verbose error reflection
    cvelistv5