PT-2026-32034 · Geonode · Geonode

Elure

·

Published

2026-04-10

·

Updated

2026-06-08

·

CVE-2026-39922

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GeoNode versions 4.0 through 4.4.5 and 5.0 through 5.0.2
Description GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 are affected by a server-side request forgery issue in the service registration endpoint. Authenticated attackers can trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Insufficient URL validation in the WMS service handler, without private IP filtering or allowlist enforcement, allows attackers to probe internal network targets, including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services.
Recommendations Update GeoNode to version 4.4.5 or later. Update GeoNode to version 5.0.2 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39922
GHSA-HW9R-6M78-W6H3
GHSA-V8F7-CG9P-W5JX
PYSEC-2026-61

Affected Products

Geonode