Information Disclosure Vulnerability in CKAN MCP Server by OnData
CVE-2026-73844

3.7LOW

Key Information:

Vendor

Ondata

Vendor
CVE Published:
14 August 2026

What is CVE-2026-73844?

CKAN MCP Server, designed for querying CKAN open data portals, contains an information disclosure flaw that exposes sensitive internal details. Before version 0.4.112, error handling in the server allowed raw upstream response bodies and internal exception messages to be displayed, revealing critical information such as hostnames, internal IP addresses, database errors, and stack traces. This vulnerability poses a risk when the server interacts with non-CKAN responses or experiences internal exceptions, potentially leading to data exposure. Users are advised to upgrade to version 0.4.112 to mitigate this risk.

Affected Version(s)

ckan-mcp-server < 0.4.112

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.