Dependency scanning
Check whether ckan is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-42031
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-42032
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2024-41675
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2025-24372
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2024-43371
Potential access to sensitive URLs via CKAN extensions (SSRF)
CVE-2025-64100
CKAN vulnerable to fixed session IDs
CVE-2024-41674
CKAN may leak Solr credentials via error message in package_search action
CVE-2025-54384
CKAN vulnerable to stored XSS in resource description
CVE-2025-64100
CKAN vulnerable to fixed session IDs
CVE-2025-54384
CKAN vulnerable to stored XSS in resource description
CVE-2024-41674
CKAN may leak Solr credentials via error message in package_search action
CVE-2023-50248
Out of memory error when submitting the dataset form with a specially-crafted field
CVE-2024-41675
CKAN has Cross-site Scripting vector in the Datatables view plugin
CVE-2024-43371
Potential access to sensitive URLs via CKAN extensions (SSRF)
CVE-2024-27097
Potential log injection in reset user endpoint in CKAN
CVE-2025-24372
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2023-32321
Ckan remote code execution and private information access via crafted resource ids
CVE-2023-32321
Ckan remote code execution and private information access via crafted resource ids
CVE-2022-43685
CVE-2022-43685
CVE-2026-42031
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
CVE-2026-41255
CKAN has CSRF exemption primed by anonymous requests
CVE-2026-42032
CKAN has Unauthenticated Authorization Bypass in `datastore_search_sql`
CVE-2026-41132
CKAN has no certificate validation on STMP connection
CVE-2022-43685
CKAN contains Improper Authentication leading to account takeover
CVE-2021-25967
Cross-site Scripting in CKAN
CVE-2024-27097
Potential log injection in reset user endpoint in CKAN
CVE-2023-50248
Out of memory error when submitting the dataset form with a specially-crafted field
CVE-2021-25967
CVE-2021-25967
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes