Record summary

CVE-2026-53573 has a selected CVSS score of 4.8 (medium).

Description

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 3.12.0, <= 3.12.12affected
>= 4.0.0-alpha.1, <= 4.0.6affected
>= 4.2.0, < 4.2.16affected
>= 4.4.0, < 4.4.11affected

org.geonetwork-opensource:geonetwork

Browse Maven / org.geonetwork-opensource:geonetwork
GitHub Advisory3.12.0 to ≤ 3.12.12affected
4.0.0-alpha.1 to ≤ 4.0.6affected
4.2.0 to < 4.2.16 · Fixed in 4.2.16affected
4.4.0 to < 4.4.11 · Fixed in 4.4.11affected

References

8