VDB
Sign up
MEDIUM6.1

PYSEC-2026-1246

CKAN vulnerable to fixed session IDs

Quick fix

PYSEC-2026-1246 — ckan: upgrade to the fixed version with the command below.

pip install --upgrade 'ckan>=2.10.9'

Details

### Impact

Session ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The attacker would need to either set a cookie on the victim's browser or steal the victim's currently valid session. Session identifiers are now regenerated after each login.

### Patches This vulnerability has been fixed in CKAN 2.10.9 and 2.11.4

### References [https://en.wikipedia.org/wiki/Session_fixation](https://en.wikipedia.org/wiki/Session_fixation)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ckan
Introduced in: 2.10.0Fixed in: 2.10.9
Fixpip install --upgrade 'ckan>=2.10.9'

References