CVE-2026-53573
Low
Low
Medium
High
Critical
CVSS Score
Vulnerability Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
References & Resources
-
https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecdsecurity-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4esecurity-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/pull/9307security-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/pull/9309security-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16security-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11security-advisories@github.com
-
https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qxsecurity-advisories@github.com
Severity Details
out of 10.0
Low
Weakness Type (CWE)
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- Description
- The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
- Exploit Likelihood
- Low
- Typical Severity
- High
- Abstraction Level
- Base
Key Information
- Published Date
- July 31, 2026
