Description
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑side request forgery
Action: Patch
AI Analysis

Impact

The vulnerability is located in the _is_within_roots function of OpenGeoS GeoLibre up to version 2.3.0. An attacker can craft input that coerces the server to perform outbound HTTP requests to arbitrary URLs. This results in a classic server‑side request forgery, allowing the attacker to reach internal network resources or exfiltrate data from the host machine. The weakness is documented as CWE‑918 and carries a CVSS score of 6.9, indicating medium risk to confidentiality and integrity.

Affected Systems

Systems running OpenGeoS GeoLibre earlier than version 2.4.0 are affected. The fix was introduced in release 2.4.0, so any deployment using 2.3.0 or earlier should be reviewed for this flaw.

Risk and Exploitability

The flaw can be triggered remotely, potentially through exposed API endpoints or web interfaces that invoke the vulnerable function. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation yet. However, because the attack path is remote and the impact could expose internal systems or data, the risk remains moderate. Mitigating measures such as vendor patching or restricting outbound requests are recommended to reduce exposure.

Generated by OpenCVE AI on September 9, 2026 at 14:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GeoLibre to version 2.4.0 or later
  • If an upgrade cannot be performed immediately, apply network controls to block outbound HTTP requests from the GeoLibre process or restrict them to known trusted destinations
  • Disable or restrict access to any API endpoints that call the _is_within_roots function until the patch is applied

Generated by OpenCVE AI on September 9, 2026 at 14:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
Title opengeos GeoLibre _is_within_roots server-side request forgery
First Time appeared Opengeos
Opengeos geolibre
Weaknesses CWE-918
CPEs cpe:2.3:a:opengeos:geolibre:*:*:*:*:*:*:*:*
Vendors & Products Opengeos
Opengeos geolibre
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Opengeos Geolibre
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T19:23:29.036Z

Reserved: 2026-09-08T13:07:21.159Z

Link: CVE-2026-86806

cve-icon Vulnrichment

Updated: 2026-09-08T19:23:19.727Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T20:18:53.630

Modified: 2026-09-09T15:33:47.627

Link: CVE-2026-86806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T20:15:01Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)