Description
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validation. An anonymous attacker could make the GeoNetwork server send requests to internal hosts that are not publicly reachable. When the outbound response was XML, the endpoint could store and return the fetched body, making the request forgery non-blind and enabling internal data disclosure, authorization bypass, and network reconnaissance. This issue is fixed in versions 4.2.17 and 4.4.12.
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery enabling internal data disclosure and authorization bypass
Action: Patch promptly
AI Analysis

Impact

GeoNetwork is a catalog application to manage spatially referenced resources. Until versions 4.2.17 and 4.4.12 the endpoint POST /api/tools/ogc/sld accepted a caller‑supplied WMS server URL and performed an unvalidated server‑side HTTP GET. An anonymous attacker can force GeoNetwork to issue requests to internal hosts that are not publicly reachable. When the fetched response is XML, the endpoint can store and return that body, turning the SSRF into a non‑blind flaw that enables internal data disclosure, authorization bypass, and network reconnaissance. The weakness is a classic Server‑Side Request Forgery and is identified as CWE‑918.

Affected Systems

The vulnerable component is the GeoNetwork core, versions earlier than 4.2.17 and 4.4.12. These releases run the SLD tool endpoint at /api/tools/ogc/sld, which accepts arbitrary URLs. Only the specified earlier versions are affected; the security fix is included in releases 4.2.17 and 4.4.12.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of < 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV. Because the attack vector is an unauthenticated POST to the SLD endpoint with an arbitrary URL, it is straightforward for any attacker who can reach the GeoNetwork service. The ability to reach internal hosts and leak data presents a serious risk to confidentiality and network security.

Generated by OpenCVE AI on September 20, 2026 at 15:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GeoNetwork to version 4.2.17 or later, or 4.4.12 or later, to apply the vendor patch that removes the unvalidated URL request.
  • Configure network firewalls or proxy rules to restrict outbound connections from the GeoNetwork server, allowing only trusted WMS endpoints and blocking internal IP ranges.
  • Implement monitoring of outbound HTTP requests from GeoNetwork to detect anomalous activity that may indicate SSRF exploitation.

Generated by OpenCVE AI on September 20, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5hx7-j24v-rffj GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validation. An anonymous attacker could make the GeoNetwork server send requests to internal hosts that are not publicly reachable. When the outbound response was XML, the endpoint could store and return the fetched body, making the request forgery non-blind and enabling internal data disclosure, authorization bypass, and network reconnaissance. This issue is fixed in versions 4.2.17 and 4.4.12.
Title GeoNetwork: Unauthenticaded Server-Side Request Forgery in SLD Tool
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 7.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:42:11.167Z

Reserved: 2026-06-17T16:44:40.996Z

Link: CVE-2026-55864

cve-icon Vulnrichment

Updated: 2026-09-16T15:42:07.946Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:16.517

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:00:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)