org.geonetwork-opensource:geonetwork vulnerabilities
CVEs whose affected-version data names the org.geonetwork-opensource:geonetwork package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-53573MediumGeoNetwork is a catalog application to manage spatially referenced resources
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits…
▾ Sunlitgeonetwork-opensource · org.geonetwork-opensource:geonetworkEPSS 0.38%via NVD
CVE-2026-39379High· 7.1GeoNetwork has reflected XSS through client-side template injection
GeoNetwork has reflected XSS through client-side template injection
▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA
CVE-2026-46487High· 7.5GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field
▾ Twilightgeonetwork-opensource · org.geonetwork-opensource:geonetworkvia GHSA