CVE-2026-42031
CRITICAL WAF: High
CVSS 9.8
Published: 2026-05-13
CWE-89
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and 2.11.5.
WAF Coverage Analysis
SQL Injection
High WAF Coverage
OWASP: A03:2021 Injection
942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| okfn | ckan | up to 2.10.10 |
| okfn | ckan | 2.11.0 - 2.11.5 |
References
- github.com (Mitigation, Vendor Advisory)