CVE-2022-50899
Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Published:Jan 13, 2026
Last Modified:Apr 7, 2026
EPS:Jan 13, 2026
EPSS Score:0.00054
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Geonetwork
Product
Opensource
Geonetwork
Opensource
Vendor
Geonetwork-opensource
Product
Geonetwork
Geonetwork-opensource
Geonetwork
Vendor
Osgeo
Product
Geonetwork
Osgeo
Geonetwork
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
