{"id":"GHSA-78x9-fhhx-v2g6","summary":"CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning","details":"## Summary\n\nThe response cache derives its key from an ambiguous string serialization of the request parameters. `canonicalizeParams` joins sorted `${key}=${value}` pairs with `&` and does not escape `&`, `=`, or the `|` field separators used in `buildCacheKey`. Two **different** logical parameter sets can therefore serialize to the **same** key and share one cache entry. Because the cached value is whatever the upstream returned for whichever request populated the entry first, an attacker can prime a colliding key so a victim's distinct query (same `server_url`) is served the attacker's cached response.\n\n## Affected code\n\n```js\n// src/utils/cache.ts\nexport function canonicalizeParams(params) {\n  const keys = Object.keys(params).sort();\n  const pairs = [];\n  for (const key of keys) {\n    const value = params[key];\n    if (value === undefined || value === null) continue;\n    const serialized = typeof value === \"object\" ? JSON.stringify(value) : String(value);\n    pairs.push(`${key}=${serialized}`);        // value not escaped\n  }\n  return pairs.join(\"&\");                        // '&' delimiter, injectable\n}\n\nexport async function buildCacheKey(serverUrl, action, params) {\n  const raw = `${serverUrl}|${action}|${canonicalizeParams(params)}`;  // '|' also unescaped\n  return sha1Hex(raw);\n}\n```\n\nConfirmed collisions (identical key):\n\n- `{ q: \"budget\", rows: 10 }`  ≡  `{ q: \"budget&rows=10\" }`  → both canonicalize to `q=budget&rows=10`\n- `{ filters: { a: \"b\" } }`  ≡  `{ filters: '{\"a\":\"b\"}' }`  → both canonicalize to `filters={\"a\":\"b\"}` (object-vs-string ambiguity)\n\nAn attacker can reproduce **any** target canonical string by injecting it into the alphabetically-first parameter, so the collision is general, not incidental.\n\n## Impact\n\n- **Cache poisoning / confusion.** On a shared cache (caching is enabled by\n  default; the Cloudflare Workers deployment uses the shared `caches.default`, and\n  a Node HTTP instance shares one in-process LRU across all clients), an attacker\n  primes a colliding entry so that another client's genuinely different query\n  receives the attacker-chosen response for the same portal.\n- **Integrity of results.** Victims receive data for a query they did not make\n  (wrong dataset list, wrong record set), undermining trust in tool output.\n- **Chains with indirect prompt injection (advisory #07).** The attacker's\n  colliding request can be one whose upstream response surfaces an\n  attacker-controlled dataset (with malicious `notes`/`title`); the victim's\n  benign query then serves that poisoned content to the model — delivering prompt\n  injection via the cache, without the victim ever querying the malicious dataset.\n\nConfidentiality impact is low (same-portal public data); the primary damage is\nintegrity. `AC:H` reflects the need for caching to be enabled and a shared\ninstance plus priming before the victim's request populates the entry.\n\n## Proof of concept\n\n`poc/cache-collision-poc.mjs` primes a single-param request and shows a victim's\ndistinct two-param request being served the attacker-primed entry:\n\n```\nattacker canonical : q=budget&rows=10\nvictim   canonical : q=budget&rows=10\nsame cache key      : true\nvictim served from cache: true\nvictim RECEIVED    : RESULT_FOR({\"q\":\"budget&rows=10\"})\nvictim EXPECTED    : RESULT_FOR({\"q\":\"budget\",\"rows\":10})\n```\n\n## Remediation\n\n- Build the cache key from an unambiguous, injection-proof encoding: hash a\n  structured, canonical JSON (with typed values) or percent-encode/escape each key\n  and value before joining, and use a separator that cannot appear in the encoded\n  fields. Include a type tag so `{a:{...}}` (object) and `{a:\"...\"}` (string)\n  never coincide.\n- Consider partitioning the cache per client/tenant on shared deployments so one\n  client cannot influence another's entries.","aliases":["CVE-2026-73846"],"modified":"2026-09-03T15:00:09.620554195Z","published":"2026-09-03T14:49:22Z","database_specific":{"cwe_ids":["CWE-345","CWE-436"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-03T14:49:22Z","nvd_published_at":"2026-08-14T17:20:36Z"},"references":[{"type":"WEB","url":"https://github.com/ondata/ckan-mcp-server/security/advisories/GHSA-78x9-fhhx-v2g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73846"},{"type":"WEB","url":"https://github.com/ondata/ckan-mcp-server/commit/8e1522f9bbfa1f3b21550f17887f60f133e24151"},{"type":"PACKAGE","url":"https://github.com/ondata/ckan-mcp-server"},{"type":"WEB","url":"https://github.com/ondata/ckan-mcp-server/releases/tag/v0.4.112"}],"affected":[{"package":{"name":"@aborruso/ckan-mcp-server","ecosystem":"npm","purl":"pkg:npm/%40aborruso/ckan-mcp-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.4.112"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-78x9-fhhx-v2g6/GHSA-78x9-fhhx-v2g6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N"}]}