CVE-2026-86806

Summary

A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.

Affected Software

VendorProductVersion RangeStatus
opengeosGeoLibre2.0affected
opengeosGeoLibre2.1affected
opengeosGeoLibre2.2affected
opengeosGeoLibre2.3.0affected
opengeosGeoLibre2.4.0unaffected

Weaknesses

  • CWE-918: Server-Side Request Forgery

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References