AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-39922.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.3CVSS 4.0 · disclosure@vulncheck.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.

Source-reported weakness categories

CWE-918

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-39922

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
geosolutionsgroupgeonode* {"versionStartIncluding":"5.0.0","versionEndExcluding":"5.0.2"}

Original records & references

PUBLISHED 2026-04-10T16:16:22-04:00
MODIFIED 2026-10-08T12:17:14-04:00
INGESTED 2026-10-10T20:50:35-04:00