PyPI: ckan
CVE-2026-42032
Safety vulnerability ID: SFTY-20260430-00489
Safety legacy ID: pyup.io-95374
Affected versions of the CKAN package are vulnerable to Authorization Bypass due to insufficient authorization enforcement in the DataStore SQL search action function. The flaw resides in the datastore_search_sql action, whose protections do not adequately restrict access, allowing requests to bypass authorization checks against the underlying PostgreSQL backend. An unauthenticated attacker can leverage this weakness to gain access to private resources and PostgreSQL system information that should otherwise be restricted.
Overview
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
Advisory
Affected versions of the CKAN package are vulnerable to Authorization Bypass due to insufficient authorization enforcement in the DataStore SQL search action function. The flaw resides in the datastore_search_sql action, whose protections do not adequately restrict access, allowing requests to bypass authorization checks against the underlying PostgreSQL backend. An unauthenticated attacker can leverage this weakness to gain access to private resources and PostgreSQL system information that should otherwise be restricted.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260430-00489/CVE-2026-42032
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42032
- https://data.safetycli.com/changelogs/ckan/
- https://github.com/advisories/GHSA-cg4x-64p3-x59h
- https://pypi.org/project/ckan
- https://github.com/ckan/ckan/security/advisories/GHSA-cg4x-64p3-x59h
- https://docs.ckan.org/en/2.10/changelog.html#v-2-10-10-2026-04-29
- https://docs.ckan.org/en/2.11/changelog.html#v-2-11-5-2026-04-29
- https://docs.ckan.org/en/2.11/extensions/plugin-interfaces.html#ckan.plugins.interfaces.IAuthFunctions
- https://docs.ckan.org/en/2.11/maintaining/configuration.html#ckan-datastore-sqlsearch-enabled
- https://nvd.nist.gov/vuln/detail/CVE-2026-42032
- https://github.com/advisories/GHSA-cg4x-64p3-x59h
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
