CVE Feed

    Dashboard / CVE / CVE-2026-39921

    CVE-2026-39921

    GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malicious URL via the doc_url parameter during document upload. Attackers can supply URLs pointing to internal network targets, loopback addresses, RFC1918 addresses, or cloud metadata services to cause the server to make requests to internal resources without SSRF mitigations such as private IP filtering or redirect validation.

    Published:Apr 10, 2026
    Last Modified:Apr 16, 2026
    EPS:Apr 10, 2026
    EPSS Score:0.0003
    CVSS Score:6.3

    Affected Products

    Vendor
    Geonode
    Product
    Geonode
    Vendor
    Geosolutionsgroup
    Product
    Geonode

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High