CVE-2026-39922Medium· 6.3▾ SunlitGeoNode contains a server-side request forgery vulnerability in the service registration endpoint
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.
geonode >= 4.0.0, < 4.4.5geonode >= 5.0.0, < 5.0.2Upgrade to a patched release:
geonode 4.4.5geonode 5.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39921Medium· 6.3GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated user…
CVE-2023-40017High· 7.5GeoNode Server Side Request forgery
CVE-2023-42439High· 7.5GeoNode vulnerable to SSRF Bypass to return internal host data
CVE-2023-26043Medium· 6.5GeoServer style upload functionality vulnerable to XML External Entity (XXE) injection
CVE-2024-27091Medium· 6.1GeoNode: Stored XSS to full account takeover
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents