Security: geonetwork/core-geonetwork
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
ACL bypass on Elasticsearch search when request body omits query fieldGHSA-582q-v28r-7cxr published
Jul 1, 2026 by juanluisrpHigh -
Open Redirect Bypass in core-geonetwork OAuth2/OIDC and Keycloak login filtersGHSA-pjp7-q6wp-97qx published
Jul 1, 2026 by juanluisrpLow -
Reflected XSS through client-side template injectionGHSA-2v4m-fw6c-g78f published
Jul 1, 2026 by juanluisrpHigh -
XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpointGHSA-2p76-gc46-5fvc published
Jun 10, 2025 by jodygarnettHigh -
Search end-point information disclosure in response headersGHSA-52rf-25hq-5m33 published
Feb 11, 2025 by jodygarnettModerate -
Remote Code Execution through Before-Script field in Local Filesystem HarvesterGHSA-cf8p-c88c-h9jf published
Sep 5, 2022 by juanluisrpModerate