Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Geonetwork
Geonetwork opensource
Geonetwork-opensource
Geonetwork-opensource geonetwork
Vendors & Products Geonetwork
Geonetwork opensource
Geonetwork-opensource
Geonetwork-opensource geonetwork

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Title Geonetwork 4.2.0 - XML External Entity (XXE)
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-14T19:20:51.974Z

Reserved: 2026-01-10T15:05:18.988Z

Link: CVE-2022-50899

cve-icon Vulnrichment

Updated: 2026-01-14T15:52:31.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T23:15:52.007

Modified: 2026-01-14T16:25:12.057

Link: CVE-2022-50899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-14T11:08:39Z

Weaknesses