CKAN SMTP Certificate Validation Vulnerability Allowing MITM Attacks

Vulnerability

A vulnerability in CKAN, an open-source data management system, allows for SMTP server spoofing with any certificate, including self-signed ones. This issue, present in CKAN versions through 2.11.4, leaves credentials and all sent emails vulnerable to man-in-the-middle attacks.

Impact

Exploitation of this vulnerability could lead to interception of credentials and emails sent via the configured SMTP server.

Remediation

Users can upgrade to CKAN version 2.10.10 or 2.11.5 to address this vulnerability.

Added: May 13, 2026, 7:31 PM
Updated: May 13, 2026, 7:31 PM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
2.5
exploitability
6.4
remediation
7.7
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.