{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gn-web-app-4.4.0---4.4.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:geonetwork-opensource:gn-web-app:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gn-web-app (4.4.0 - 4.4.11)","gn-web-app (4.0.0 - 4.2.16)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GeoNetwork"],"content_html":"\u003cp\u003eGeoNetwork version 4.4.0 through 4.4.11 and 4.0.0 through 4.2.16 are affected by an unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-55864. The vulnerability resides in the SLD tooling endpoint located at /api/tools/ogc/sld. This endpoint accepts a WMS server URL parameter from an unauthenticated user and performs a server-side HTTP GET request to the provided destination without validation.\u003c/p\u003e\n\u003cp\u003eIf the requested resource returns XML content, the application may store and display the output, turning this into a non-blind SSRF. Attackers can leverage this to conduct network reconnaissance against internal infrastructure, interact with internal services that are not publicly exposed, or potentially exfiltrate sensitive information from internal files if they return XML-based responses. This poses a significant risk to internal network segmentation and data confidentiality.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to probe internal networks, bypass firewall restrictions to access internal services, and exfiltrate internal configuration data or other sensitive resources formatted as XML. This could lead to full internal network reconnaissance and unauthorized data disclosure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to GeoNetwork 4.4.12 or 4.2.17 to remediate CVE-2026-55864.\u003c/li\u003e\n\u003cli\u003eImplement network egress filtering on the GeoNetwork server to restrict outbound connections to known, trusted WMS server endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy detection rules to monitor for unauthorized requests to the /api/tools/ogc/sld endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T00:51:54Z","date_published":"2026-09-10T00:51:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-geonetwork-ssrf/","summary":"An unauthenticated server-side request forgery vulnerability (CVE-2026-55864) in the GeoNetwork SLD tool allows attackers to perform unauthorized outbound requests and potentially disclose internal XML data.","title":"Unauthenticated Server-Side Request Forgery in GeoNetwork Web Module","url":"https://feed.craftedsignal.io/briefs/2026-09-geonetwork-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Gn-Web-App (4.4.0 - 4.4.11)","version":"https://jsonfeed.org/version/1.1"}