id: PYSEC-2026-1246 published: "2026-07-07T16:03:08.876313Z" modified: "2026-07-07T17:23:54.547830Z" aliases: - CVE-2025-64100 - GHSA-2hvh-cw5c-8q8q summary: CKAN vulnerable to fixed session IDs details: "### Impact\n\nSession ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The attacker would need to either set a cookie on the victim's browser or steal the victim's currently valid session. Session identifiers are now regenerated after each login.\n\n### Patches\nThis vulnerability has been fixed in CKAN 2.10.9 and 2.11.4\n\n### References\n[https://en.wikipedia.org/wiki/Session_fixation](https://en.wikipedia.org/wiki/Session_fixation)" affected: - package: name: ckan ecosystem: PyPI purl: pkg:pypi/ckan ranges: - type: ECOSYSTEM events: - introduced: 2.10.0 - fixed: 2.10.9 - introduced: 2.11.0 - fixed: 2.11.4 versions: - 2.10.0 - 2.10.1 - 2.10.3 - 2.10.4 - 2.10.5 - 2.10.6 - 2.10.7 - 2.10.8 - 2.11.0 - 2.11.1 - 2.11.2 - 2.11.3 references: - type: WEB url: https://github.com/ckan/ckan/security/advisories/GHSA-2hvh-cw5c-8q8q - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-64100 - type: WEB url: https://github.com/ckan/ckan/commit/c2fe437f88be850a6edf7a32470772428819fab5 - type: PACKAGE url: https://github.com/ckan/ckan - type: PACKAGE url: https://pypi.org/project/ckan - type: ADVISORY url: https://github.com/advisories/GHSA-2hvh-cw5c-8q8q severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N