Vulnerability Description
GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
Related Weaknesses (CWE)
References
- https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34
- https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4
- https://github.com/geonetwork/core-geonetwork/pull/9307
- https://github.com/geonetwork/core-geonetwork/pull/9309
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16
- https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11
- https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp
FAQ
What is CVE-2026-53573?
CVE-2026-53573 is a documented vulnerability. GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakA...
How severe is CVE-2026-53573?
CVSS scoring is not yet available for CVE-2026-53573. Check NVD for updates.
Is there a patch for CVE-2026-53573?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.