<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:geonetwork-Opensource:gn-Web-App:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ageonetwork-opensourcegn-web-app/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 00:51:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ageonetwork-opensourcegn-web-app/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Server-Side Request Forgery in GeoNetwork Web Module</title><link>https://feed.craftedsignal.io/briefs/2026-09-geonetwork-ssrf/</link><pubDate>Thu, 10 Sep 2026 00:51:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-geonetwork-ssrf/</guid><description>An unauthenticated server-side request forgery vulnerability (CVE-2026-55864) in the GeoNetwork SLD tool allows attackers to perform unauthorized outbound requests and potentially disclose internal XML data.</description><content:encoded><![CDATA[<p>GeoNetwork version 4.4.0 through 4.4.11 and 4.0.0 through 4.2.16 are affected by an unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-55864. The vulnerability resides in the SLD tooling endpoint located at /api/tools/ogc/sld. This endpoint accepts a WMS server URL parameter from an unauthenticated user and performs a server-side HTTP GET request to the provided destination without validation.</p>
<p>If the requested resource returns XML content, the application may store and display the output, turning this into a non-blind SSRF. Attackers can leverage this to conduct network reconnaissance against internal infrastructure, interact with internal services that are not publicly exposed, or potentially exfiltrate sensitive information from internal files if they return XML-based responses. This poses a significant risk to internal network segmentation and data confidentiality.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthenticated attackers to probe internal networks, bypass firewall restrictions to access internal services, and exfiltrate internal configuration data or other sensitive resources formatted as XML. This could lead to full internal network reconnaissance and unauthorized data disclosure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade to GeoNetwork 4.4.12 or 4.2.17 to remediate CVE-2026-55864.</li>
<li>Implement network egress filtering on the GeoNetwork server to restrict outbound connections to known, trusted WMS server endpoints.</li>
<li>Deploy detection rules to monitor for unauthorized requests to the /api/tools/ogc/sld endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>