---
id: CVE-2026-53573
title: GeoNetwork is a catalog application to manage spatially referenced resources
summary: >-
  GeoNetwork is a catalog application to manage spatially referenced resources.
  From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in
  GeonetworkOAuth2LoginAuthenticationFilter and
  KeycloakAuthenticationProcessingFilter permits…
severity: medium
cwe:
  - CWE-601
vendor: geonetwork-opensource
product: 'org.geonetwork-opensource:geonetwork'
affected:
  - 'org.geonetwork-opensource:geonetwork >= 3.12.0, <= 3.12.12'
  - 'org.geonetwork-opensource:geonetwork >= 4.0.0-alpha.1, <= 4.0.6'
  - 'org.geonetwork-opensource:geonetwork >= 4.2.0, <= 4.2.15'
  - 'org.geonetwork-opensource:geonetwork >= 4.4.0, <= 4.4.10'
patched:
  - 'org.geonetwork-opensource:geonetwork 4.2.16'
  - 'org.geonetwork-opensource:geonetwork 4.4.11'
published: '2026-07-31'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:30:11.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53573'
references:
  - url: >-
      https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd
    label: security-advisories@github.com
  - url: >-
      https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e
    label: security-advisories@github.com
  - url: 'https://github.com/geonetwork/core-geonetwork/pull/9307'
    label: security-advisories@github.com
  - url: 'https://github.com/geonetwork/core-geonetwork/pull/9309'
    label: security-advisories@github.com
  - url: 'https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16'
    label: security-advisories@github.com
  - url: 'https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11'
    label: security-advisories@github.com
  - url: >-
      https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-pjp7-q6wp-97qx'
tags:
  - nvd
  - ghsa
  - maven
epss: 0.00648
epssPercentile: 0.48865
aliases:
  - GHSA-pjp7-q6wp-97qx
ecosystem: maven
ingestedAt: '2026-07-31T23:04:59.965Z'
---

## Overview

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-53573)

Affected packages:

- `org.geonetwork-opensource:geonetwork >= 3.12.0, <= 3.12.12`
- `org.geonetwork-opensource:geonetwork >= 4.0.0-alpha.1, <= 4.0.6`
- `org.geonetwork-opensource:geonetwork >= 4.2.0, <= 4.2.15`
- `org.geonetwork-opensource:geonetwork >= 4.4.0, <= 4.4.10`

Patched in:

- `org.geonetwork-opensource:geonetwork 4.2.16`
- `org.geonetwork-opensource:geonetwork 4.4.11`

Source: https://github.com/advisories/GHSA-pjp7-q6wp-97qx
