CVE-2026-53573

Source
https://cve.org/CVERecord?id=CVE-2026-53573
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53573.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-53573
Aliases
Published
2026-07-31T22:16:25.110Z
Modified
2026-08-12T16:41:09.314058Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
core-geonetwork has an Open Redirect Bypass
Details

GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53573.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "4.4.0"
                },
                {
                    "fixed": "4.4.11"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-601"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/geonetwork/core-geonetwork

Affected ranges

Type
GIT
Repo
https://github.com/geonetwork/core-geonetwork
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.12.0"
        },
        {
            "last_affected": "3.12.12"
        },
        {
            "introduced": "4.0.0-alpha.1"
        },
        {
            "last_affected": "4.0.6"
        },
        {
            "introduced": "4.2.0"
        },
        {
            "fixed": "4.2.16"
        }
    ]
}

Affected versions

4.*
4.2.0
4.2.1
4.2.10
4.2.11
4.2.13
4.2.14
4.2.15
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
4.4.0
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9

Database specific

vanir_signatures
[
    {
        "id": "CVE-2026-53573-073f3129",
        "target": {
            "file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "263599846214460334619102329815613283729",
                "328932304889579822127449237321284064657",
                "114444348311386099257759273371924733781",
                "298803900482021256422768131516949656625",
                "243197886452319559389682775151367858429",
                "321035715150664461865703888033550086272",
                "213795837555464118419878867526480384059",
                "90076472495935864964556700350512784755",
                "12910697600300778627837788437816795865",
                "300165366232268396013998074529442396172",
                "232498631452373401785375766198255393302",
                "237083200127223003577229969061120839795",
                "215379284649105890623589052290326519660",
                "40462760693520610958624779650725262639",
                "89340039631359535571576037250349581502",
                "132995259821265959067561323160813739427",
                "48996132125067518713981535260322060291",
                "242509312090648684381284735926006604983",
                "93512848584364392260863423586663847417",
                "254815479331827537532646833309473098369",
                "338612040923574056489001898705077837151",
                "28851006699412088516791884934606896512",
                "148172246185773003026152090303170446342",
                "83824971697946441846051326574233667149",
                "17266668298490415809101115981802180471",
                "33994481219728029628188860108862064077",
                "181704388714316561141561253878264498837",
                "262791953966184383066292044676729399220",
                "237349829063183958570393587304062026430",
                "211132982868805920767771640970394032663",
                "277688618690289374042098186237780123976",
                "165792113998260356178801696457089134700",
                "42637560282392174557661792702681365429",
                "287360656268380893286997503507683544576",
                "77433192463014331482289171406293634643",
                "137371767986170914859240577745550046078",
                "15137169493042178564613215030815416143",
                "330755484287199557722533374782789538280",
                "305563964228298578069293493893388597068",
                "192947258018663808485343664810893434934"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-0792630f",
        "target": {
            "file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "263599846214460334619102329815613283729",
                "328932304889579822127449237321284064657",
                "114444348311386099257759273371924733781",
                "298803900482021256422768131516949656625",
                "243197886452319559389682775151367858429",
                "321035715150664461865703888033550086272",
                "213795837555464118419878867526480384059",
                "90076472495935864964556700350512784755",
                "12910697600300778627837788437816795865",
                "300165366232268396013998074529442396172",
                "232498631452373401785375766198255393302",
                "237083200127223003577229969061120839795",
                "215379284649105890623589052290326519660",
                "40462760693520610958624779650725262639",
                "89340039631359535571576037250349581502",
                "132995259821265959067561323160813739427",
                "48996132125067518713981535260322060291",
                "242509312090648684381284735926006604983",
                "93512848584364392260863423586663847417",
                "254815479331827537532646833309473098369",
                "338612040923574056489001898705077837151",
                "28851006699412088516791884934606896512",
                "148172246185773003026152090303170446342",
                "83824971697946441846051326574233667149",
                "17266668298490415809101115981802180471",
                "33994481219728029628188860108862064077",
                "181704388714316561141561253878264498837",
                "262791953966184383066292044676729399220",
                "237349829063183958570393587304062026430",
                "211132982868805920767771640970394032663",
                "277688618690289374042098186237780123976",
                "165792113998260356178801696457089134700",
                "42637560282392174557661792702681365429",
                "287360656268380893286997503507683544576",
                "77433192463014331482289171406293634643",
                "137371767986170914859240577745550046078",
                "15137169493042178564613215030815416143",
                "330755484287199557722533374782789538280",
                "305563964228298578069293493893388597068",
                "192947258018663808485343664810893434934"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-13863778",
        "target": {
            "function": "successfulAuthentication",
            "file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "39811858981903786467115182548749449442",
            "length": 2066.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-53573-70ec8c7f",
        "target": {
            "function": "successfulAuthentication",
            "file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "152192103216774655264870392295212505223",
            "length": 2932.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-53573-76f57bbb",
        "target": {
            "file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "177736723777120798823367481908130102256",
                "274842374522458215899602595207338577302",
                "244081900460784094501221813653643283588",
                "170445749898024705296173554904612443038",
                "252007394123783787343894969168707002531",
                "286425599896669864653133570236052711623",
                "138168963969692143955582594370943613226",
                "96933354254705296814757469256034189631",
                "43658015714810605441104405590618498172",
                "116376614802623132823531685657498236198",
                "198596055296323989405568503158056301887",
                "284233872003178850489976272012312976091",
                "68326509537890848197955062874127147201",
                "301631744562428757574439428372737041137",
                "265672882123927210811416936381396973798",
                "135691629746925183663672376128446119327",
                "339524251333035701483726960837364424380",
                "157286396146036405236114581491710482586",
                "221625248463888709153464291481634001129",
                "254246835691526861219580402111520290887",
                "35240249306195434966277147181081755615",
                "86732968715834218349117007641756959807",
                "242221181082573958534545242780949903498",
                "321084047166929652888193080327488695802",
                "7503625032547512359087067145406593943",
                "189415138053496318470665557433327972343",
                "88150427529349172594656731855423496249"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-833964a1",
        "target": {
            "file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "98116081869317680424870510954313930652",
                "274842374522458215899602595207338577302",
                "184275049276355830901447182494319231347",
                "83508324395529416347108727137974885681",
                "1858902006611410789211586561888612869",
                "189333854748735701850659126414684999120",
                "107139148809460637168799844564334615184",
                "234760020471300600100774636167697483805",
                "58975812546931745352417145155793519794",
                "44164522791792955738890968337235472162",
                "242982890218925323871560989529452331976",
                "259510831139492459002716111158589103711",
                "15506328150711173810011930679940553913",
                "185359244944939329689046457757225595364",
                "17767688916430946231253272120586766322",
                "83439499041023126649311939939097176429",
                "94712780187572118731658966770446531708",
                "242221181082573958534545242780949903498",
                "321084047166929652888193080327488695802",
                "77371509002581521752109495245253364274",
                "304393572501618506678046058948100881526",
                "339988031543743852047813282201495733879"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-97ba502b",
        "target": {
            "function": "successfulAuthentication",
            "file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "152192103216774655264870392295212505223",
            "length": 2932.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-53573-a30ffb95",
        "target": {
            "file": "core/src/main/java/org/fao/geonet/kernel/security/keycloak/KeycloakAuthenticationProcessingFilter.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "98116081869317680424870510954313930652",
                "274842374522458215899602595207338577302",
                "184275049276355830901447182494319231347",
                "83508324395529416347108727137974885681",
                "1858902006611410789211586561888612869",
                "189333854748735701850659126414684999120",
                "107139148809460637168799844564334615184",
                "234760020471300600100774636167697483805",
                "58975812546931745352417145155793519794",
                "44164522791792955738890968337235472162",
                "242982890218925323871560989529452331976",
                "259510831139492459002716111158589103711",
                "15506328150711173810011930679940553913",
                "185359244944939329689046457757225595364",
                "17767688916430946231253272120586766322",
                "83439499041023126649311939939097176429",
                "94712780187572118731658966770446531708",
                "242221181082573958534545242780949903498",
                "321084047166929652888193080327488695802",
                "77371509002581521752109495245253364274",
                "304393572501618506678046058948100881526",
                "339988031543743852047813282201495733879"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-a53eed84",
        "target": {
            "function": "successfulAuthentication",
            "file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "39811858981903786467115182548749449442",
            "length": 2066.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-53573-db6ebd7f",
        "target": {
            "function": "determineTargetUrl",
            "file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "85389637205707260086243951307811310764",
            "length": 921.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Function"
    },
    {
        "id": "CVE-2026-53573-e39c1395",
        "target": {
            "file": "core/src/main/java/org/fao/geonet/kernel/security/openidconnect/GeonetworkOAuth2LoginAuthenticationFilter.java"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "177736723777120798823367481908130102256",
                "274842374522458215899602595207338577302",
                "244081900460784094501221813653643283588",
                "170445749898024705296173554904612443038",
                "252007394123783787343894969168707002531",
                "286425599896669864653133570236052711623",
                "138168963969692143955582594370943613226",
                "96933354254705296814757469256034189631",
                "43658015714810605441104405590618498172",
                "116376614802623132823531685657498236198",
                "198596055296323989405568503158056301887",
                "284233872003178850489976272012312976091",
                "68326509537890848197955062874127147201",
                "301631744562428757574439428372737041137",
                "265672882123927210811416936381396973798",
                "135691629746925183663672376128446119327",
                "339524251333035701483726960837364424380",
                "157286396146036405236114581491710482586",
                "221625248463888709153464291481634001129",
                "254246835691526861219580402111520290887",
                "35240249306195434966277147181081755615",
                "86732968715834218349117007641756959807",
                "242221181082573958534545242780949903498",
                "321084047166929652888193080327488695802",
                "7503625032547512359087067145406593943",
                "189415138053496318470665557433327972343",
                "88150427529349172594656731855423496249"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
        "signature_type": "Line"
    },
    {
        "id": "CVE-2026-53573-effee142",
        "target": {
            "function": "determineTargetUrl",
            "file": "core/src/main/java/jeeves/config/springutil/JeevesNodeAwareLogoutSuccessHandler.java"
        },
        "deprecated": false,
        "digest": {
            "function_hash": "85389637205707260086243951307811310764",
            "length": 921.0
        },
        "signature_version": "v1",
        "source": "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
        "signature_type": "Function"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53573.json"
vanir_signatures_modified
"2026-08-12T16:41:09Z"