VYPR
High severity7.3NVD Advisory· Published Sep 8, 2026

CVE-2026-86806

CVE-2026-86806

Description

A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.

Affected products

2
  • Opengeos/Geolibrereferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2.3.0

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.