CVE-2026-53573: Geonetwork Core-Geonetwork
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Affected products
- Geonetwork Core-Geonetwork: from 3.12.0, up to and including 3.12.12; from 4.0.0-alpha.1, up to and including 4.0.6; from 4.2.0, before 4.2.16 (fixed in 4.2.16); from 4.4.0, before 4.4.11 (fixed in 4.4.11)
Published 2026-07-31. Last modified 2026-09-10.