Vulnerability Description
GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation. Attackers can probe internal network targets including loopback addresses, RFC1918 private IP ranges, link-local addresses, and cloud metadata services by exploiting insufficient URL validation in the WMS service handler without private IP filtering or allowlist enforcement.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Geosolutionsgroup | Geonode | >= 4.0.0, < 4.4.5 |
Related Weaknesses (CWE)
References
- https://github.com/GeoNode/geonode/security/advisories/GHSA-hw9r-6m78-w6h3
- https://www.vulncheck.com/advisories/geonode-ssrf-via-service-registrationThird Party Advisory
FAQ
What is CVE-2026-39922?
CVE-2026-39922 is a vulnerability with a CVSS score of 6.3 (MEDIUM). GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attacke...
How severe is CVE-2026-39922?
CVE-2026-39922 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39922?
Check the references section above for vendor advisories and patch information. Affected products include: Geosolutionsgroup Geonode.