CVE-2026-86806
opengeos GeoLibre _is_within_roots server-side request forgery
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
| CWE | CWE-918 |
| Vendor | opengeos |
| Product | geolibre |
| Published | Sep 8, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for opengeos geolibre
Be the first to know when new high vulnerabilities affecting opengeos geolibre are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
opengeos / GeoLibre
2.0 2.1 2.2 2.3.0
References
vuldb.com: https://vuldb.com/vuln/399812 vuldb.com: https://vuldb.com/vuln/399812/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86806 vuldb.com: https://vuldb.com/submit/911055 github.com: https://github.com/opengeos/GeoLibre/issues/1573 github.com: https://github.com/opengeos/GeoLibre/pull/1571 github.com: https://github.com/opengeos/GeoLibre/commit/b745f62e29fa37364686525a21eee5e5c0f8a369 github.com: https://github.com/opengeos/GeoLibre/releases/tag/v2.4.0 github.com: https://github.com/opengeos/GeoLibre/
Credits
๐ Customeres (VulDB User)