github.com
https://github.com/geonetwork/core-geonetwork CVE-2026-53573
MEDIUM
core-geonetwork has an Open Redirect Bypass
Record summary
CVE-2026-53573 has a selected CVSS score of 4.8 (medium).
Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
core-geonetworkBrowse geonetwork / core-geonetwork | CVE List | >= 3.12.0, <= 3.12.12 | affected |
| >= 4.0.0-alpha.1, <= 4.0.6 | affected | ||
| >= 4.2.0, < 4.2.16 | affected | ||
| >= 4.4.0, < 4.4.11 | affected | ||
org.geonetwork-opensource:geonetworkBrowse Maven / org.geonetwork-opensource:geonetwork | GitHub Advisory | 3.12.0 to ≤ 3.12.12 | affected |
| 4.0.0-alpha.1 to ≤ 4.0.6 | affected | ||
| 4.2.0 to < 4.2.16 · Fixed in 4.2.16 | affected | ||
| 4.4.0 to < 4.4.11 · Fixed in 4.4.11 | affected |
References
8github.com
https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd github.com
https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e github.com
https://github.com/geonetwork/core-geonetwork/pull/9307 github.com
https://github.com/geonetwork/core-geonetwork/pull/9309 github.com
https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16 github.com
https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11 github.comConfirmation
https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx