Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
GeoNetwork has reflected XSS through client-side template injection High
CVE-2026-39379 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 1, 2026
Timonheu Credited to Timonheu, juanluisrp, and jodygarnett juanluisrp juanluisrp
jodygarnett jodygarnett
GeoNetwork has ACL bypass on Elasticsearch search when request body omits query field High
CVE-2026-46487 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 1, 2026
jrdnull Credited to jrdnull and juanluisrp juanluisrp juanluisrp
core-geonetwork has an Open Redirect Bypass Moderate
CVE-2026-53573 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 31, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and juanluisrp RacerZ-fighting RacerZ-fighting
juanluisrp juanluisrp
ProTip! Advisories are also available from the GraphQL API