GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53573.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.4.11"
}
]
}
],
"cwe_ids": [
"CWE-601"
],
"cna_assigner": "GitHub_M"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "3.12.0"
},
{
"last_affected": "3.12.12"
},
{
"introduced": "4.0.0-alpha.1"
},
{
"last_affected": "4.0.6"
},
{
"introduced": "4.2.0"
},
{
"fixed": "4.2.16"
}
]
}
[
{
"id": "CVE-2026-53573-073f3129",
"target": {
"file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"263599846214460334619102329815613283729",
"328932304889579822127449237321284064657",
"114444348311386099257759273371924733781",
"298803900482021256422768131516949656625",
"243197886452319559389682775151367858429",
"321035715150664461865703888033550086272",
"213795837555464118419878867526480384059",
"90076472495935864964556700350512784755",
"12910697600300778627837788437816795865",
"300165366232268396013998074529442396172",
"232498631452373401785375766198255393302",
"237083200127223003577229969061120839795",
"215379284649105890623589052290326519660",
"40462760693520610958624779650725262639",
"89340039631359535571576037250349581502",
"132995259821265959067561323160813739427",
"48996132125067518713981535260322060291",
"242509312090648684381284735926006604983",
"93512848584364392260863423586663847417",
"254815479331827537532646833309473098369",
"338612040923574056489001898705077837151",
"28851006699412088516791884934606896512",
"148172246185773003026152090303170446342",
"83824971697946441846051326574233667149",
"17266668298490415809101115981802180471",
"33994481219728029628188860108862064077",
"181704388714316561141561253878264498837",
"262791953966184383066292044676729399220",
"237349829063183958570393587304062026430",
"211132982868805920767771640970394032663",
"277688618690289374042098186237780123976",
"165792113998260356178801696457089134700",
"42637560282392174557661792702681365429",
"287360656268380893286997503507683544576",
"77433192463014331482289171406293634643",
"137371767986170914859240577745550046078",
"15137169493042178564613215030815416143",
"330755484287199557722533374782789538280",
"305563964228298578069293493893388597068",
"192947258018663808485343664810893434934"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-0792630f",
"target": {
"file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"263599846214460334619102329815613283729",
"328932304889579822127449237321284064657",
"114444348311386099257759273371924733781",
"298803900482021256422768131516949656625",
"243197886452319559389682775151367858429",
"321035715150664461865703888033550086272",
"213795837555464118419878867526480384059",
"90076472495935864964556700350512784755",
"12910697600300778627837788437816795865",
"300165366232268396013998074529442396172",
"232498631452373401785375766198255393302",
"237083200127223003577229969061120839795",
"215379284649105890623589052290326519660",
"40462760693520610958624779650725262639",
"89340039631359535571576037250349581502",
"132995259821265959067561323160813739427",
"48996132125067518713981535260322060291",
"242509312090648684381284735926006604983",
"93512848584364392260863423586663847417",
"254815479331827537532646833309473098369",
"338612040923574056489001898705077837151",
"28851006699412088516791884934606896512",
"148172246185773003026152090303170446342",
"83824971697946441846051326574233667149",
"17266668298490415809101115981802180471",
"33994481219728029628188860108862064077",
"181704388714316561141561253878264498837",
"262791953966184383066292044676729399220",
"237349829063183958570393587304062026430",
"211132982868805920767771640970394032663",
"277688618690289374042098186237780123976",
"165792113998260356178801696457089134700",
"42637560282392174557661792702681365429",
"287360656268380893286997503507683544576",
"77433192463014331482289171406293634643",
"137371767986170914859240577745550046078",
"15137169493042178564613215030815416143",
"330755484287199557722533374782789538280",
"305563964228298578069293493893388597068",
"192947258018663808485343664810893434934"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-13863778",
"target": {
"function": "successfulAuthentication",
"file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
},
"deprecated": false,
"digest": {
"function_hash": "39811858981903786467115182548749449442",
"length": 2066.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Function"
},
{
"id": "CVE-2026-53573-70ec8c7f",
"target": {
"function": "successfulAuthentication",
"file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
},
"deprecated": false,
"digest": {
"function_hash": "152192103216774655264870392295212505223",
"length": 2932.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Function"
},
{
"id": "CVE-2026-53573-76f57bbb",
"target": {
"file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"177736723777120798823367481908130102256",
"274842374522458215899602595207338577302",
"244081900460784094501221813653643283588",
"170445749898024705296173554904612443038",
"252007394123783787343894969168707002531",
"286425599896669864653133570236052711623",
"138168963969692143955582594370943613226",
"96933354254705296814757469256034189631",
"43658015714810605441104405590618498172",
"116376614802623132823531685657498236198",
"198596055296323989405568503158056301887",
"284233872003178850489976272012312976091",
"68326509537890848197955062874127147201",
"301631744562428757574439428372737041137",
"265672882123927210811416936381396973798",
"135691629746925183663672376128446119327",
"339524251333035701483726960837364424380",
"157286396146036405236114581491710482586",
"221625248463888709153464291481634001129",
"254246835691526861219580402111520290887",
"35240249306195434966277147181081755615",
"86732968715834218349117007641756959807",
"242221181082573958534545242780949903498",
"321084047166929652888193080327488695802",
"7503625032547512359087067145406593943",
"189415138053496318470665557433327972343",
"88150427529349172594656731855423496249"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-833964a1",
"target": {
"file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"98116081869317680424870510954313930652",
"274842374522458215899602595207338577302",
"184275049276355830901447182494319231347",
"83508324395529416347108727137974885681",
"1858902006611410789211586561888612869",
"189333854748735701850659126414684999120",
"107139148809460637168799844564334615184",
"234760020471300600100774636167697483805",
"58975812546931745352417145155793519794",
"44164522791792955738890968337235472162",
"242982890218925323871560989529452331976",
"259510831139492459002716111158589103711",
"15506328150711173810011930679940553913",
"185359244944939329689046457757225595364",
"17767688916430946231253272120586766322",
"83439499041023126649311939939097176429",
"94712780187572118731658966770446531708",
"242221181082573958534545242780949903498",
"321084047166929652888193080327488695802",
"77371509002581521752109495245253364274",
"304393572501618506678046058948100881526",
"339988031543743852047813282201495733879"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-97ba502b",
"target": {
"function": "successfulAuthentication",
"file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
},
"deprecated": false,
"digest": {
"function_hash": "152192103216774655264870392295212505223",
"length": 2932.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Function"
},
{
"id": "CVE-2026-53573-a30ffb95",
"target": {
"file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"98116081869317680424870510954313930652",
"274842374522458215899602595207338577302",
"184275049276355830901447182494319231347",
"83508324395529416347108727137974885681",
"1858902006611410789211586561888612869",
"189333854748735701850659126414684999120",
"107139148809460637168799844564334615184",
"234760020471300600100774636167697483805",
"58975812546931745352417145155793519794",
"44164522791792955738890968337235472162",
"242982890218925323871560989529452331976",
"259510831139492459002716111158589103711",
"15506328150711173810011930679940553913",
"185359244944939329689046457757225595364",
"17767688916430946231253272120586766322",
"83439499041023126649311939939097176429",
"94712780187572118731658966770446531708",
"242221181082573958534545242780949903498",
"321084047166929652888193080327488695802",
"77371509002581521752109495245253364274",
"304393572501618506678046058948100881526",
"339988031543743852047813282201495733879"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-a53eed84",
"target": {
"function": "successfulAuthentication",
"file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
},
"deprecated": false,
"digest": {
"function_hash": "39811858981903786467115182548749449442",
"length": 2066.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Function"
},
{
"id": "CVE-2026-53573-db6ebd7f",
"target": {
"function": "determineTargetUrl",
"file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
},
"deprecated": false,
"digest": {
"function_hash": "85389637205707260086243951307811310764",
"length": 921.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Function"
},
{
"id": "CVE-2026-53573-e39c1395",
"target": {
"file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"177736723777120798823367481908130102256",
"274842374522458215899602595207338577302",
"244081900460784094501221813653643283588",
"170445749898024705296173554904612443038",
"252007394123783787343894969168707002531",
"286425599896669864653133570236052711623",
"138168963969692143955582594370943613226",
"96933354254705296814757469256034189631",
"43658015714810605441104405590618498172",
"116376614802623132823531685657498236198",
"198596055296323989405568503158056301887",
"284233872003178850489976272012312976091",
"68326509537890848197955062874127147201",
"301631744562428757574439428372737041137",
"265672882123927210811416936381396973798",
"135691629746925183663672376128446119327",
"339524251333035701483726960837364424380",
"157286396146036405236114581491710482586",
"221625248463888709153464291481634001129",
"254246835691526861219580402111520290887",
"35240249306195434966277147181081755615",
"86732968715834218349117007641756959807",
"242221181082573958534545242780949903498",
"321084047166929652888193080327488695802",
"7503625032547512359087067145406593943",
"189415138053496318470665557433327972343",
"88150427529349172594656731855423496249"
]
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
"signature_type": "Line"
},
{
"id": "CVE-2026-53573-effee142",
"target": {
"function": "determineTargetUrl",
"file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
},
"deprecated": false,
"digest": {
"function_hash": "85389637205707260086243951307811310764",
"length": 921.0
},
"signature_version": "v1",
"source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53573.json"
"2026-08-12T16:41:09Z"