Advisories for Maven/Org.geonetwork-Opensource/Gn-Web-App package

2026

GeoNetwork Web Module: Unauthenticaded Server-Side Request Forgery in SLD Tool

An unauthenticated server-side request forgery vulnerability lets any anonymous user make the GeoNetwork server issue arbitrary outbound HTTP requests. This gives an external attacker a position inside the server's network, making it possible to make internal requests no matter if the response is XML-type or not. The SLD tooling endpoint POST /api/tools/ogc/sld takes a caller-supplied WMS server URL and performs a server-side HTTP GET to it, with no validation. The …

2025