Moderate severityNVD Advisory· Published Jul 31, 2026· Updated Aug 3, 2026
core-geonetwork has an Open Redirect Bypass
CVE-2026-53573
Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.geonetwork-opensource:geonetworkMaven | >= 3.12.0, <= 3.12.12 | — |
org.geonetwork-opensource:geonetworkMaven | >= 4.0.0-alpha.1, <= 4.0.6 | — |
org.geonetwork-opensource:geonetworkMaven | >= 4.2.0, < 4.2.16 | 4.2.16 |
org.geonetwork-opensource:geonetworkMaven | >= 4.4.0, < 4.4.11 | 4.4.11 |
Affected products
1- Range: 3.12.0 - 4.2.16, 4.4.11
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-pjp7-q6wp-97qxghsaADVISORY
- github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecdghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4eghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/pull/9307ghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/pull/9309ghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/releases/tag/4.2.16ghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/releases/tag/4.4.11ghsax_refsource_MISCWEB
- github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qxghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.