Security: geonetwork/core-geonetwork
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Map feature popup renders KML/vector description and attributes as raw HTML via innerHTMLGHSA-jcv2-3cfh-v9h2 published
Aug 31, 2026 by jodygarnettCritical -
Unauthenticated file upload via missing authorization on formatter upload endpointGHSA-mh22-prqr-vf42 published
Aug 31, 2026 by jodygarnettHigh -
Unauthenticated Server-Side Request Forgery in SLD ToolGHSA-5hx7-j24v-rffj published
Aug 31, 2026 by jodygarnettHigh -
Reflected XSS via unsanitized Javascript SinkGHSA-5pq9-ppfw-p83j published
Aug 31, 2026 by jodygarnettHigh -
ACL bypass on Elasticsearch search when request body omits query fieldGHSA-582q-v28r-7cxr published
Jul 1, 2026 by juanluisrpHigh -
Open Redirect Bypass in core-geonetwork OAuth2/OIDC and Keycloak login filtersGHSA-pjp7-q6wp-97qx published
Jul 1, 2026 by juanluisrpLow -
Reflected XSS through client-side template injectionGHSA-2v4m-fw6c-g78f published
Jul 1, 2026 by juanluisrpHigh -
Remote Code Execution via unsafe Saxon XSLT processor configuration in formatterGHSA-x898-729x-cc3r published
Aug 31, 2026 by jodygarnettCritical -
XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpointGHSA-2p76-gc46-5fvc published
Jun 10, 2025 by jodygarnettHigh -
Search end-point information disclosure in response headersGHSA-52rf-25hq-5m33 published
Feb 11, 2025 by jodygarnettModerate