CVE-2026-53573 PUBLISHED

core-geonetwork has an Open Redirect Bypass

Assigner: GitHub_M
Reserved: 09.06.2026 Published: 31.07.2026 Updated: 31.07.2026

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor geonetwork
Product core-geonetwork
Versions
  • Version >= 3.12.0, <= 3.12.12 is affected
  • Version >= 4.0.0-alpha.1, <= 4.0.6 is affected
  • Version >= 4.2.0, < 4.2.16 is affected
  • Version >= 4.4.0, < 4.4.11 is affected

References

Problem Types

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CWE