Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
History

Wed, 14 Jan 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Geonetwork
Geonetwork opensource
Geonetwork-opensource
Geonetwork-opensource geonetwork
Vendors & Products Geonetwork
Geonetwork opensource
Geonetwork-opensource
Geonetwork-opensource geonetwork

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.
Title Geonetwork 4.2.0 - XML External Entity (XXE)
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-13T22:51:45.416Z

Updated: 2026-01-14T19:20:51.974Z

Reserved: 2026-01-10T15:05:18.988Z

Link: CVE-2022-50899

cve-icon Vulnrichment

Updated: 2026-01-14T15:52:31.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T23:15:52.007

Modified: 2026-01-14T16:25:12.057

Link: CVE-2022-50899

cve-icon Redhat

No data.