{"schema_version":1,"title":"GeoNetwork-opensource GeoNetwork vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in GeoNetwork-opensource GeoNetwork: 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55864, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/geonetwork","json_url":"https://junglewise.ai/threats/technologies/geonetwork.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/geonetwork","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":6,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":6,"last_365_days":6},"latest":[{"cve":"CVE-2026-55864","cvss":4,"epss":0.0059,"slug":"cve-2026-55864-geonetwork-unauthenticated-server-side-request-forgery-in-sld","title":"GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:16.517+00:00","url":"https://junglewise.ai/threats/cve-2026-55864-geonetwork-unauthenticated-server-side-request-forgery-in-sld"},{"cve":"CVE-2026-63219","cvss":8.6,"epss":0.0047,"slug":"cve-2026-63219-geonetwork-unauthenticated-file-upload-via-missing-authorization","title":"GeoNetwork unauthenticated file upload via missing authorization in formatter endpoint","severity":"high","exploited":false,"published_at":"2026-09-03T18:17:22.997+00:00","url":"https://junglewise.ai/threats/cve-2026-63219-geonetwork-unauthenticated-file-upload-via-missing-authorization"},{"cve":"CVE-2026-58400","cvss":9.1,"epss":0.0119,"slug":"cve-2026-58400-geonetwork-remote-code-execution-via-unsafe-saxon-xslt-processor","title":"GeoNetwork remote code execution via unsafe Saxon XSLT processor","severity":"critical","exploited":false,"published_at":"2026-09-03T18:17:22.827+00:00","url":"https://junglewise.ai/threats/cve-2026-58400-geonetwork-remote-code-execution-via-unsafe-saxon-xslt-processor"},{"cve":"CVE-2026-53573","cvss":3.1,"epss":0.0065,"slug":"cve-2026-53573-geonetwork-open-redirect-in-oauth2-and-keycloak-login-filters","title":"GeoNetwork open redirect in OAuth2 and Keycloak login filters","severity":"medium","exploited":false,"published_at":"2026-07-31T23:17:24.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53573-geonetwork-open-redirect-in-oauth2-and-keycloak-login-filters"},{"cve":"CVE-2026-46487","cvss":7.5,"slug":"cve-2026-46487-geonetwork-acl-bypass-in-elasticsearch-search-api","title":"GeoNetwork ACL bypass in Elasticsearch search API","severity":"high","exploited":false,"published_at":"2026-07-01T17:57:13+00:00","url":"https://junglewise.ai/threats/cve-2026-46487-geonetwork-acl-bypass-in-elasticsearch-search-api"},{"cve":"CVE-2026-39379","cvss":7.1,"slug":"cve-2026-39379-geonetwork-reflected-xss-via-client-side-template-injection-in","title":"GeoNetwork reflected XSS via client-side template injection in error pages","severity":"high","exploited":false,"published_at":"2026-07-01T17:56:51+00:00","url":"https://junglewise.ai/threats/cve-2026-39379-geonetwork-reflected-xss-via-client-side-template-injection-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"GeoNetwork-opensource GeoNetwork","slug":"geonetwork","vendor":{"name":"GeoNetwork-opensource","slug":"geonetwork-opensource","url":"https://junglewise.ai/threats/vendors/geonetwork-opensource"},"aliases":[],"category":"web-application","homepage":"https://geonetwork-opensource.org/","repo_url":"https://github.com/geonetwork/core-geonetwork","description":"GeoNetwork is a catalog application to manage spatially referenced resources.","url":"https://junglewise.ai/threats/technologies/geonetwork"},"most_severe":[{"cve":"CVE-2026-58400","cvss":9.1,"epss":0.0119,"slug":"cve-2026-58400-geonetwork-remote-code-execution-via-unsafe-saxon-xslt-processor","title":"GeoNetwork remote code execution via unsafe Saxon XSLT processor","severity":"critical","exploited":false,"published_at":"2026-09-03T18:17:22.827+00:00","url":"https://junglewise.ai/threats/cve-2026-58400-geonetwork-remote-code-execution-via-unsafe-saxon-xslt-processor"},{"cve":"CVE-2026-63219","cvss":8.6,"epss":0.0047,"slug":"cve-2026-63219-geonetwork-unauthenticated-file-upload-via-missing-authorization","title":"GeoNetwork unauthenticated file upload via missing authorization in formatter endpoint","severity":"high","exploited":false,"published_at":"2026-09-03T18:17:22.997+00:00","url":"https://junglewise.ai/threats/cve-2026-63219-geonetwork-unauthenticated-file-upload-via-missing-authorization"},{"cve":"CVE-2026-46487","cvss":7.5,"slug":"cve-2026-46487-geonetwork-acl-bypass-in-elasticsearch-search-api","title":"GeoNetwork ACL bypass in Elasticsearch search API","severity":"high","exploited":false,"published_at":"2026-07-01T17:57:13+00:00","url":"https://junglewise.ai/threats/cve-2026-46487-geonetwork-acl-bypass-in-elasticsearch-search-api"},{"cve":"CVE-2026-39379","cvss":7.1,"slug":"cve-2026-39379-geonetwork-reflected-xss-via-client-side-template-injection-in","title":"GeoNetwork reflected XSS via client-side template injection in error pages","severity":"high","exploited":false,"published_at":"2026-07-01T17:56:51+00:00","url":"https://junglewise.ai/threats/cve-2026-39379-geonetwork-reflected-xss-via-client-side-template-injection-in"},{"cve":"CVE-2026-55864","cvss":4,"epss":0.0059,"slug":"cve-2026-55864-geonetwork-unauthenticated-server-side-request-forgery-in-sld","title":"GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:16.517+00:00","url":"https://junglewise.ai/threats/cve-2026-55864-geonetwork-unauthenticated-server-side-request-forgery-in-sld"},{"cve":"CVE-2026-53573","cvss":3.1,"epss":0.0065,"slug":"cve-2026-53573-geonetwork-open-redirect-in-oauth2-and-keycloak-login-filters","title":"GeoNetwork open redirect in OAuth2 and Keycloak login filters","severity":"medium","exploited":false,"published_at":"2026-07-31T23:17:24.667+00:00","url":"https://junglewise.ai/threats/cve-2026-53573-geonetwork-open-redirect-in-oauth2-and-keycloak-login-filters"}],"generated_at":"2026-09-26T14:07:00.158513+00:00"}