As an open source software leader, GeoCat staff are part of the global response to the present wave of AI-assisted security vulnerability reports.
We wish to reassure our customers that their systems were patched in advance of last months GeoNetwork public disclosure.
Our actions in working with security researchers to address and resolve vulnerabilities resulted in the publication of "Coordinate Vulnerability and Exposure" (CVE) records, which in turn have been picked up by your national or regional agencies. This may have resulted in GeoNetwork administrators being contacted directly.
This represents the system operating as it should: using the CVE system to communicate to the security agencies. If you have any questions please contact support, and check the product release notes for the patched vulnerabilities:
- CVE-2026-63219 Unauthenticated file upload via missing authorization on formatter upload endpoint
- CVE-2026-55864 Unauthenticated Server-Side Request Forgery in SLD Tool
- CVE-2026-57582 Reflected XSS via unsanitized Javascript Sink
- CVE-2026-58400 Remote Code Execution via unsafe Saxon XSLT processor configuration in formatter
- CVE-2026-69130 Map feature popup renders KML/vector description and attributes as raw HTML via innerHTML
We are pleased to represent our customers as part of the GeoNetwork community, providing notifications as releases are announced.
Project development and maintenance is a costly undertaking. While we are serious about providing IP-free and open software, we also rely on the financial commitment of those depending on it.
If your organization uses GeoNetwork, and you have been contacted about the above CVE's, do consider contacting GeoCat as we would love an opportunity to work with you.
You may also wish to contact us about the Cyber Resilience Act (CRA) of September 11 reporting requirements and learn how this affects use of open-source technologies in Europe.