HIGH GitHub
CVE-2026-55864
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
### Summary
An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make internal requests no matter if the response is XML-type or not.
The SLD tooling endpoint `POST /api/tools/ogc/sld` takes a caller-supplied **WMS server URL** and performs a **server-side HTTP GET** to it, with no validation. The fetched
Affected Products
- maven/org.geonetwork-opensource:gn-web-app >= 4.4.0, <= 4.4.11
- maven/org.geonetwork-opensource:gn-web-app >= 4.0.0, <= 4.2.16
References
- https://github.com/advisories/GHSA-5hx7-j24v-rffj
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-5hx7-j24v-rffj
- https://github.com/geonetwork/core-geonetwork/pull/9343
- https://github.com/advisories/GHSA-5hx7-j24v-rffj
This high severity vulnerability was published on 2026-09-09 via GitHub. Affected: maven/org.geonetwork-opensource:gn-web-app >= 4.4.0, <= 4.4.11, maven/org.geonetwork-opensource:gn-web-app >= 4.0.0, <= 4.2.16.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.