CVE-2026-39922
Description
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
geonodePyPI | >= 4.0.0, < 4.4.5 | 4.4.5 |
geonodePyPI | >= 5.0.0, < 5.0.2 | 5.0.2 |
Affected products
2cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*range: >=4.0.0,<4.4.5
- (no CPE)range: <=4.4.5, <=5.0.2
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-hw9r-6m78-w6h3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-39922ghsaADVISORY
- www.vulncheck.com/advisories/geonode-ssrf-via-service-registrationnvdThird Party AdvisoryWEB
- github.com/GeoNode/geonode/releases/tag/4.4.5ghsaWEB
- github.com/GeoNode/geonode/releases/tag/5.0.2ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/geonode/PYSEC-2026-61.yamlghsaWEB
- github.com/GeoNode/geonode/security/advisories/GHSA-hw9r-6m78-w6h3nvd
News mentions
0No linked articles in our index yet.