CVE-2026-39921

Source
https://cve.org/CVERecord?id=CVE-2026-39921
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39921.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-39921
Aliases
Published
2026-04-10T19:52:49.924Z
Modified
2026-07-16T03:48:30.939106743Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L CVSS Calculator
Summary
GeoNode < 4.4.5, 5.0.2 SSRF via Document Upload
Details

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malicious URL via the doc_url parameter during document upload. Attackers can supply URLs pointing to internal network targets, loopback addresses, RFC1918 addresses, or cloud metadata services to cause the server to make requests to internal resources without SSRF mitigations such as private IP filtering or redirect validation.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39921.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.0.0"
                },
                {
                    "fixed": "4.4.5"
                },
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.0.2"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.0.0"
                },
                {
                    "fixed": "4.4.5"
                },
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.0.2"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "4.0"
                },
                {
                    "fixed": "4.4.5"
                },
                {
                    "introduced": "5.0"
                },
                {
                    "fixed": "5.0.2"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/geonode/geonode

Affected ranges

Type
GIT
Repo
https://github.com/geonode/geonode
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.0-RC1
1.0-beta
1.1-RC1
1.1-beta
1.1-beta2
2.*
2.0
2.0b11
2.0b12
2.0b28
2.0b44
2.0b45
2.0b47
2.0b48
2.0b52
2.0b54
2.0b61
2.0b62
2.0b64
2.0c1
2.0c10
2.0c12
2.0c13
2.0c2
2.0c4
2.0c6
2.10.3
2.10.4
2.10rc5
2.4
2.4.dev20141024171719
2.4a10
2.4a11
2.4a12
2.4a13
2.4a14
2.4a15
2.4a16
2.4a17
2.4a18
2.4a19
2.4a20
2.4a21
2.4a22
2.4a23
2.4a24
2.4a25
2.4a26
2.4a27
2.4a28
2.4a29
2.4a30
2.4a31
2.4a32
2.4a33
2.4a34
2.4a4
2.4a7
2.4a8
2.4a9
2.4b10
2.4b11
2.4b12
2.4b13
2.4b14
2.4b17
2.4b6
2.4b7
2.4b8
2.4b9
2.4c3
2.4c4
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
2.5.15
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.9
2.5.9+thefinal1
2.5.9+thefinal2
2.5.9+thefinal3
2.5.9+thefinal4
2.5.9+thefinal5
2.5.9.dev20170116091118
3.*
3.0
debian/2.*
debian/2.0.0+beta11
debian/2.0.0+beta12
debian/2.0.0+beta28
debian/2.0.0+beta44
debian/2.0.0+beta45
debian/2.0.0+beta47
debian/2.0.0+beta48
debian/2.0.0+beta52
debian/2.0.0+beta54
debian/2.0.0+beta61
debian/2.0.0+beta62
debian/2.0.0+beta64
debian/2.0.0+rc1
debian/2.0.0+rc10
debian/2.0.0+rc12
debian/2.0.0+rc13
debian/2.0.0+rc2
debian/2.0.0+rc4
debian/2.0.0+rc6
debian/2.0.0+thefinal0
debian/2.0.0+thefinal1
debian/2.0.0+thefinal2
debian/2.0.0+thefinal3
debian/2.0.0+thefinal4
debian/2.0.0+thefinal5
debian/2.0.0+thefinal6
debian/2.0.0+thefinal7
debian/2.0b54
debian/2.4.0+alpha10
debian/2.4.0+alpha11
debian/2.4.0+alpha12
debian/2.4.0+alpha13
debian/2.4.0+alpha14
debian/2.4.0+alpha15
debian/2.4.0+alpha16
debian/2.4.0+alpha17
debian/2.4.0+alpha18
debian/2.4.0+alpha19
debian/2.4.0+alpha20
debian/2.4.0+alpha21
debian/2.4.0+alpha22
debian/2.4.0+alpha23
debian/2.4.0+alpha24
debian/2.4.0+alpha25
debian/2.4.0+alpha26
debian/2.4.0+alpha27
debian/2.4.0+alpha28
debian/2.4.0+alpha29
debian/2.4.0+alpha30
debian/2.4.0+alpha31
debian/2.4.0+alpha32
debian/2.4.0+alpha33
debian/2.4.0+alpha34
debian/2.4.0+alpha4
debian/2.4.0+alpha7
debian/2.4.0+alpha8
debian/2.4.0+alpha9
debian/2.4.0+beta10
debian/2.4.0+beta11
debian/2.4.0+beta12
debian/2.4.0+beta13
debian/2.4.0+beta14
debian/2.4.0+beta17
debian/2.4.0+beta6
debian/2.4.0+beta7
debian/2.4.0+beta8
debian/2.4.0+beta9
debian/2.4.0+dev20141024171719
debian/2.4.0+rc3
debian/2.4.0+rc4
debian/2.4.0+thefinal0
debian/2.5.1+thefinal0
debian/2.5.10+thefinal0
debian/2.5.11+thefinal0
debian/2.5.12+thefinal0
debian/2.5.13+thefinal0
debian/2.5.14+thefinal0
debian/2.5.15+thefinal0
debian/2.5.2+thefinal0
debian/2.5.3+thefinal0
debian/2.5.4+thefinal0
debian/2.5.5+thefinal0
debian/2.5.6+thefinal0
debian/2.5.7+thefinal0
debian/2.5.9+dev20170116091118
debian/2.5.9+thefinal0
debian/2.5.9+thefinal1
debian/2.5.9+thefinal2
debian/2.5.9+thefinal3
debian/2.5.9+thefinal4
debian/2.5.9+thefinal5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39921.json"