GHSA-5hx7-j24v-rffj
HIGHCVE-2026-55864An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make internal requests no matter if the response is XML-type or not.
- Affected
- >= 4.4.0, <= 4.4.11
- Fixed in
- 4.4.12
- Weakness
- CWE-918
- Published
- 2026-09-09
- Source
- github