THREAT OPS › Threat News › [GHSA] GHSA-78x9-fhhx-v2g6 (medium) — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
[GHSA] GHSA-78x9-fhhx-v2g6 (medium) — CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
GHSA-78x9-fhhx-v2g6 Severity: medium CVE: CVE-2026-73846
CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning
## Summary
The response cache derives its key from an ambiguous string serialization of the request parameters. `canonicalizeParams` joins sorted `${key}=${value}` pairs with `&` and does not escape `&`, `=`, or the `|` field separators used in `buil
Indicators of compromise
- CVE-2026-73846cve
Original source: https://github.com/advisories/GHSA-78x9-fhhx-v2g6