{"id":"PYSEC-2026-1246","summary":"CKAN vulnerable to fixed session IDs","details":"### Impact\n\nSession ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The attacker would need to either set a cookie on the victim's browser or steal the victim's currently valid session. Session identifiers are now regenerated after each login.\n\n### Patches\nThis vulnerability has been fixed in CKAN 2.10.9 and 2.11.4\n\n### References\n[https://en.wikipedia.org/wiki/Session_fixation](https://en.wikipedia.org/wiki/Session_fixation)","aliases":["CVE-2025-64100","GHSA-2hvh-cw5c-8q8q"],"modified":"2026-07-07T17:47:27.135173282Z","published":"2026-07-07T16:03:08.876313Z","references":[{"type":"WEB","url":"https://github.com/ckan/ckan/security/advisories/GHSA-2hvh-cw5c-8q8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64100"},{"type":"WEB","url":"https://github.com/ckan/ckan/commit/c2fe437f88be850a6edf7a32470772428819fab5"},{"type":"PACKAGE","url":"https://github.com/ckan/ckan"},{"type":"PACKAGE","url":"https://pypi.org/project/ckan"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2hvh-cw5c-8q8q"}],"affected":[{"package":{"name":"ckan","ecosystem":"PyPI","purl":"pkg:pypi/ckan"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.10.0"},{"fixed":"2.10.9"},{"introduced":"2.11.0"},{"fixed":"2.11.4"}]}],"versions":["2.10.0","2.10.1","2.10.3","2.10.4","2.10.5","2.10.6","2.10.7","2.10.8","2.11.0","2.11.1","2.11.2","2.11.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ckan/PYSEC-2026-1246.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"}]}