core-geonetwork has an Open Redirect Bypass — GHSA-PJP7-Q6WP-97QX
GitHub · GitHub · GHSA-PJP7-Q6WP-97QX
ID
GHSA-PJP7-Q6WP-97QX
GHSA-PJP7-Q6WP-97QX
Date
Source
GitHub
GitHub
Vendor
GitHub
GitHub
Threat
medium
medium
Summary
### Summary GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application URLs. This affects both supported SSO login methods: OAuth2/OIDC and Keycloak. ### Details Both the OAuth2/OIDC and Keycloak login filters validate the client-supplied post-login redirect target before…
Timeline
- Published by source
- 2026-08-01
Risk context
- Reported severity or threat level: medium.
- Review exposure for the affected product or family: maven: org.geonetwork-opensource:geonetwork.
Product
maven: org.geonetwork-opensource:geonetwork
What to do
General, cautious steps (verify details in the official source):
- Review exposure and plan remediation based on risk and environment.
- Identify affected product versions in your inventory and verify whether you are impacted.
- Apply vendor patches/updates or recommended mitigations as soon as available.
- Read the official advisory for exact affected versions and remediation steps.
Official advisory
Evidence and provenance
- Canonical advisory ID
- GHSA-PJP7-Q6WP-97QX
- Source
- GitHub
- Vendor
- GitHub
- Published by source
- 2026-08-01
- Last source activity
- 2026-08-01
- Additional identifiers
- CVE-2026-53573
- Curated by
- hlukh.ch
Related advisories and connections
These advisories are connected by shared CVE, product, vendor, source, or time signals.