CVE-2026-53573

Summary

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Affected Software

VendorProductVersion RangeStatus
geonetworkcore-geonetwork>= 3.12.0, <= 3.12.12affected
geonetworkcore-geonetwork>= 4.0.0-alpha.1, <= 4.0.6affected
geonetworkcore-geonetwork>= 4.2.0, < 4.2.16affected
geonetworkcore-geonetwork>= 4.4.0, < 4.4.11affected

Weaknesses

  • CWE-601: CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

References