MEDIUM6.1
PYSEC-2026-1246
CKAN vulnerable to fixed session IDs
Quick fix
PYSEC-2026-1246 — ckan: upgrade to the fixed version with the command below.
pip install --upgrade 'ckan>=2.10.9'Details
### Impact
Session ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The attacker would need to either set a cookie on the victim's browser or steal the victim's currently valid session. Session identifiers are now regenerated after each login.
### Patches This vulnerability has been fixed in CKAN 2.10.9 and 2.11.4
### References [https://en.wikipedia.org/wiki/Session_fixation](https://en.wikipedia.org/wiki/Session_fixation)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ckan/ckan/security/advisories/GHSA-2hvh-cw5c-8q8q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-64100[ADVISORY]
- https://github.com/ckan/ckan/commit/c2fe437f88be850a6edf7a32470772428819fab5[WEB]
- https://github.com/ckan/ckan[PACKAGE]
- https://pypi.org/project/ckan[PACKAGE]
- https://github.com/advisories/GHSA-2hvh-cw5c-8q8q[ADVISORY]