GeoNetwork fixes vulnerability chain enabling remote command execution

The GeoNetwork project published security advisories concerning unauthenticated formatter uploads and a Saxon XSLT flaw. Versions 4.4.12 and 4.2.17 also address CVE-2026-58400, which has a CVSS score of 9.1.
