Sploitus

CVE-2022-50899

No indexed exploits for CVE-2022-50899 yet

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files through the baseURL parameter in PDF creation requests.

Affected products
Geonetwork, Core-Geonetwork
Osgeo Geonetwork
≤ 4.2.0
Fix
Available
CVSS 4.0
8.7 HIGH
CVSS 3.1
6.5 MEDIUM
EPSS
0.5% (38th percentile)
Weakness
CWE-611
NVD status
Analyzed
Published
2026-01-13
CVE-2022-50899 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2022-50899 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2022-50899 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.