THREAT OPS › Threat News › [GHSA] GHSA-5hx7-j24v-rffj (high) — GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
[GHSA] GHSA-5hx7-j24v-rffj (high) — GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
GHSA-5hx7-j24v-rffj Severity: high CVE: CVE-2026-55864
GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool
### Summary An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make
Indicators of compromise
- CVE-2026-55864cve
Original source: https://github.com/advisories/GHSA-5hx7-j24v-rffj