PT-2026-59092 · Pypi · Ckan
Published
2026-07-13
·
Updated
2026-07-13
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U |
Impact
Configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks.
Patches
The vulnerability has been patched in CKAN 2.10.10 and CKAN 2.11.5
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ckan