Disclosure summary
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.
Source-reported weakness categories
CWE-918
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-39922
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| geosolutionsgroup | geonode | * {"versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.2"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- www.vulncheck.com — Third Party Advisory
PUBLISHED 2026-04-10T16:16:22-04:00
MODIFIED 2026-10-08T12:17:14-04:00
INGESTED 2026-10-10T20:50:35-04:00