Skip to content
archivevulnerability · 09 Sep 2026 · 23:43 UTC

GHSA-5hx7-j24v-rffj: GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

VULNCVE-2026-55864source · GTH
HIGHHigh-risk vulnerability

last 60 dispatches · spectrum

### Summary An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make internal requests no matter if the response is XML-type or not. The SLD tooling endpoint `POST /api/tools/ogc/sld` takes a caller-supplied **WMS server URL** and performs a **server-side HTTP GET** to it, with no validation. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected