Junglewise Threat Intelligence

CVE-2026-39922: GeoNode SSRF in service registration endpoint

CVE-2026-39922 · Severity: medium · CVSS 6.3 · Published 2026-04-10

Technologies: Geonode, geonode (PyPI). Vendors: PyPI.

Executive brief

GeoNode, an open-source platform for sharing geospatial data, contains a security flaw in its service registration feature. An authenticated user can trick the system into making unauthorized network requests to internal servers or cloud management interfaces that are normally hidden from the public internet. This could allow an attacker to map out private internal networks or access sensitive configuration data from cloud environments.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the GeoNode service registration endpoint, specifically within the WMS service handler. The root cause is insufficient URL validation and a lack of private IP filtering or allowlist enforcement during form validation. An authenticated attacker can submit a crafted service URL to trigger outbound requests from the server. This allows for probing of internal network targets, including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services (e.g., IMDS). The vulnerability is addressed in versions subsequent to 4.4.5 and 5.0.2.

Affected products

  • GeoNode GeoNode 4.0.0 to 4.4.5, 5.0.0 to 5.0.2

Timeline

  • 2026-04-10: advisory: Initial advisory published by VulnCheck
  • 2026-04-10: disclosed

References

Related threats