{"data":{"id":"50724c5e-9e66-4cb8-9c1b-b00658c06f94","title":"GHSA-798p-78g2-v556: @aborruso/ckan-mcp-server has SSRF via DNS-name → internal IP — incomplete fix of CVE-2026-53509","summary":"A server package called `@aborruso/ckan-mcp-server` has a security flaw called SSRF (server-side request forgery, where a server makes requests to places it shouldn't). The flaw exists in a validation function that checks hostnames but never resolves them using DNS (the system that translates website names into IP addresses). An attacker can supply a hostname that looks safe but actually resolves to internal addresses like `127.0.0.1` or `169.254.169.254` (cloud metadata), allowing them to steal internal data. This bug is still present in the latest version (0.4.107) and has bypassed two previous attempted fixes.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-798p-78g2-v556","publishedAt":"2026-09-22T14:51:20.000Z","cveId":"CVE-2026-61612","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":["@aborruso/ckan-mcp-server@<= 0.4.107 (fixed: 0.4.108)"],"affectedVendors":[],"affectedVendorsRaw":["@aborruso/ckan-mcp-server","Model Context Protocol"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00221,"patchAvailable":true,"disclosureDate":"2026-09-22T14:51:20.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}