VYPR
Medium severity6.3NVD Advisory· Published Apr 10, 2026· Updated Apr 16, 2026

CVE-2026-39922

CVE-2026-39922

Description

GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
geonodePyPI
>= 4.0.0, < 4.4.54.4.5
geonodePyPI
>= 5.0.0, < 5.0.25.0.2

Affected products

2
  • cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:*range: >=4.0.0,<4.4.5
    • (no CPE)range: <=4.4.5, <=5.0.2

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.