THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5hx7-j24v-rffj (high) — GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

[GHSA] GHSA-5hx7-j24v-rffj (high) — GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

medgithub_advisoriesPublished 2026-09-09

GHSA-5hx7-j24v-rffj Severity: high CVE: CVE-2026-55864

GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

### Summary An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5hx7-j24v-rffj