{"id":"CVE-2026-53573","title":"GeoNetwork is a catalog application to manage spatially referenced resources","summary":"GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…","severity":"medium","cwe":["CWE-601"],"vendor":"geonetwork-opensource","product":"org.geonetwork-opensource:geonetwork","affected":["org.geonetwork-opensource:geonetwork >= 3.12.0, <= 3.12.12","org.geonetwork-opensource:geonetwork >= 4.0.0-alpha.1, <= 4.0.6","org.geonetwork-opensource:geonetwork >= 4.2.0, <= 4.2.15","org.geonetwork-opensource:geonetwork >= 4.4.0, <= 4.4.10"],"patched":["org.geonetwork-opensource:geonetwork 4.2.16","org.geonetwork-opensource:geonetwork 4.4.11"],"published":"2026-07-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:30:11.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-53573","references":[{"url":"https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/pull/9307","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/pull/9309","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11","label":"security-advisories@github.com"},{"url":"https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-pjp7-q6wp-97qx"}],"tags":["nvd","ghsa","maven"],"epss":0.00377,"epssPercentile":0.31467,"aliases":["GHSA-pjp7-q6wp-97qx"],"ecosystem":"maven","ingestedAt":"2026-07-31T23:04:59.965Z","slug":"CVE-2026-53573","body":"## Overview\n\nGeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-53573)\n\nAffected packages:\n\n- `org.geonetwork-opensource:geonetwork >= 3.12.0, <= 3.12.12`\n- `org.geonetwork-opensource:geonetwork >= 4.0.0-alpha.1, <= 4.0.6`\n- `org.geonetwork-opensource:geonetwork >= 4.2.0, <= 4.2.15`\n- `org.geonetwork-opensource:geonetwork >= 4.4.0, <= 4.4.10`\n\nPatched in:\n\n- `org.geonetwork-opensource:geonetwork 4.2.16`\n- `org.geonetwork-opensource:geonetwork 4.4.11`\n\nSource: https://github.com/advisories/GHSA-pjp7-q6wp-97qx","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}