CVE-2026-86806: Server-Side Request Forgery in opengeos GeoLibre
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
AI Analysis
Technical Summary
A server-side request forgery vulnerability has been identified in the _is_within_roots function of opengeos GeoLibre versions 2.0, 2.1, 2.2, and 2.3.0. This flaw allows an unauthenticated remote attacker to manipulate server requests, potentially causing the server to make unintended requests. The issue is addressed by upgrading to GeoLibre version 2.4.0. No known exploits are reported in the wild at this time.
Potential Impact
An attacker can remotely exploit this vulnerability to cause the server to make forged requests, which may lead to unauthorized access to internal resources or information disclosure depending on the server's network environment. The CVSS score of 6.9 reflects a medium impact with low complexity and no required privileges or user interaction.
Mitigation Recommendations
Upgrade opengeos GeoLibre to version 2.4.0 or later to remediate this vulnerability. No other official mitigation or temporary fix is documented. Patch status is confirmed by the vendor's recommendation to upgrade.
CVE-2026-86806: Server-Side Request Forgery in opengeos GeoLibre
Description
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
CVSS v4.0
Score 6.9medium
Affected software
pkg:github/opengeos/GeoLibrecpe:2.3:a:opengeos:geolibre:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A server-side request forgery vulnerability has been identified in the _is_within_roots function of opengeos GeoLibre versions 2.0, 2.1, 2.2, and 2.3.0. This flaw allows an unauthenticated remote attacker to manipulate server requests, potentially causing the server to make unintended requests. The issue is addressed by upgrading to GeoLibre version 2.4.0. No known exploits are reported in the wild at this time.
Potential Impact
An attacker can remotely exploit this vulnerability to cause the server to make forged requests, which may lead to unauthorized access to internal resources or information disclosure depending on the server's network environment. The CVSS score of 6.9 reflects a medium impact with low complexity and no required privileges or user interaction.
Mitigation Recommendations
Upgrade opengeos GeoLibre to version 2.4.0 or later to remediate this vulnerability. No other official mitigation or temporary fix is documented. Patch status is confirmed by the vendor's recommendation to upgrade.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-08T13:07:21.159Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa0609bacd9273b491c7442
Added to database: 09/08/2026, 19:23:07 UTC
Last enriched: 09/08/2026, 19:37:42 UTC
Last updated: 09/08/2026, 20:09:17 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.