Executive brief
CKAN, an open-source data portal platform, fails to validate security certificates when connecting to email (SMTP) servers. This allows an attacker to intercept or spoof communications, potentially exposing sensitive email content and server credentials. Organizations using CKAN for data management and distribution should update to the latest patched versions to ensure their automated email communications remain secure.
Technical details
CKAN contains a vulnerability where it fails to perform proper certificate validation (CWE-295) when establishing an SMTP connection. Because the software does not verify the authenticity of the SMTP server's certificate, it will accept any certificate, including self-signed ones. A network-positioned attacker can exploit this by performing a man-in-the-middle (MITM) attack to spoof the configured SMTP server. This allows the attacker to capture plaintext email credentials and intercept all outgoing email traffic. The issue is fixed in CKAN versions 2.10.10 and 2.11.5.
Affected products
- ckan ckan >= 2.11.0, <= 2.11.4
- ckan ckan < 2.10.10
Timeline
- 2026-04-29: disclosed
- 2026-04-29: patched
- 2026-04-29: advisory
References
- https://api.github.com/users/francisbergin
- https://github.com/francisbergin
- https://api.github.com/users/francisbergin/gists%7B/gist_id%7D
- https://api.github.com/users/francisbergin/repos
- https://avatars.githubusercontent.com/u/198925343?v=4
- https://api.github.com/users/francisbergin/events%7B/privacy%7D