CVE-2026-41132: CKAN has no certificate validation on STMP connection
Configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41132 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →