CVE-2026-53573 Details
Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
A vulnerability allowing open redirects has been identified in GeoNetwork, a catalog application for managing spatially referenced resources. This issue affects versions 3.12.0 through 4.2.15 and 4.4.0 through 4.4.10. The vulnerability arises from improper validation of redirect URLs in the OAuth2 and Keycloak authentication filters, allowing attackers to redirect users to external sites after login. Although the application attempts to restrict redirects to relative, in-application URLs, the validation can be bypassed, leading to potential phishing attacks or exploitation of other external vulnerabilities.
Users should upgrade to GeoNetwork versions 4.2.16 or 4.4.11. Instructions for downloading these versions are available on the GeoNetwork GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | [email protected] |