THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-78x9-fhhx-v2g6 (medium) — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

[GHSA] GHSA-78x9-fhhx-v2g6 (medium) — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

medgithub_advisoriesPublished 2026-09-03

GHSA-78x9-fhhx-v2g6 Severity: medium CVE: CVE-2026-73846

CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning

## Summary

The response cache derives its key from an ambiguous string serialization of the request parameters. `canonicalizeParams` joins sorted `${key}=${value}` pairs with `&` and does not escape `&`, `=`, or the `|` field separators used in `buil

Indicators of compromise

Original source: https://github.com/advisories/GHSA-78x9-fhhx-v2g6