CVE-2026-53573Medium▾ SunlitGeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.geonetwork-opensource:geonetwork >= 3.12.0, <= 3.12.12org.geonetwork-opensource:geonetwork >= 4.0.0-alpha.1, <= 4.0.6org.geonetwork-opensource:geonetwork >= 4.2.0, <= 4.2.15org.geonetwork-opensource:geonetwork >= 4.4.0, <= 4.4.10Patched in:
org.geonetwork-opensource:geonetwork 4.2.16org.geonetwork-opensource:geonetwork 4.4.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
CVE-2024-0953Medium· 6.1When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code
CVE-2026-34442Medium· 5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework
CVE-2025-3155High· 7.4A flaw was found in Yelp
CVE-2023-6291High· 7.1A flaw was found in the redirect_uri validation logic in Keycloak