PT-2026-36112 · Pypi · Pygeoapi
Elnimo-00
·
Published
2026-04-29
·
Updated
2026-05-09
·
CVE-2026-42352
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pygeoapi versions 0.23.0 through 0.23.2
Description
OGC API process execution requests can utilize the
subscriber object to make requests to internal HTTP services. This allows for unauthorized interaction with internal network resources.Recommendations
Update to version 0.23.3.
As a temporary workaround, disable process based resources in the pygeoapi configuration.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pygeoapi