CVE-2026-39921 Details
Description
GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malicious URL via the doc_url parameter during document upload. Attackers can supply URLs pointing to internal network targets, loopback addresses, RFC1918 addresses, or cloud metadata services to cause the server to make requests to internal resources without SSRF mitigations such as private IP filtering or redirect validation.
A server-side request forgery (SSRF) vulnerability has been identified in GeoNode versions 4.0 prior to 4.4.5 and 5.0 prior to 5.0.2. This vulnerability allows authenticated users with document upload permissions to send arbitrary outbound HTTP requests. By providing a malicious URL through the doc_url parameter during document upload, users can direct the server to make requests to internal network targets, loopback addresses, RFC1918 addresses, or cloud metadata services. The vulnerability exists without proper SSRF mitigations, such as private IP filtering or redirect validation.
Users can upgrade to GeoNode versions 4.4.5 or 5.0.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| geosolutionsgroup geonode | >= 4.0.0, < 4.4.5 >= 5.0.0, < 5.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | CVE Modified | [email protected] |
| Apr 15, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | New CVE Received | [email protected] |