Metrics
Affected Vendors & Products
Thu, 16 Apr 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 16 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement. | GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement. |
| Title | GeoNode < 4.4.5, 5.0.2 SSRF via Service Registration | GeoNode SSRF via Service Registration |
| References |
|
Wed, 15 Apr 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geosolutionsgroup
Geosolutionsgroup geonode |
|
| CPEs | cpe:2.3:a:geosolutionsgroup:geonode:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Geosolutionsgroup
Geosolutionsgroup geonode |
|
| Metrics |
cvssV3_1
|
Mon, 13 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geonode
Geonode geonode |
|
| Vendors & Products |
Geonode
Geonode geonode |
Fri, 10 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement. | |
| Title | GeoNode < 4.4.5, 5.0.2 SSRF via Service Registration | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-10T19:53:05.159Z
Updated: 2026-04-16T00:43:12.705Z
Reserved: 2026-04-07T20:57:06.210Z
Link: CVE-2026-39922
Updated: 2026-04-13T17:36:04.385Z
Status : Modified
Published: 2026-04-10T20:16:22.270
Modified: 2026-04-16T01:16:10.950
Link: CVE-2026-39922
No data.