CVE-2025-58175Medium· 6.5▾ SunlitGeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.5%
A GeoServer that uses ENTITY_RESOLUTION_ALLOWLIST may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF).
This vulnerability requires that GeoServer is set up to use a proxy base URL and the ENTITY_RESOLUTION_ALLOWLIST (default since 2.25.0):
This vulnerability allows an attacker to cause GeoServer to make requests to an unintended location.
GeoServer installations are only affected by this vulnerability if they use a proxy base URL that does not contain a URL path or end with a slash (e.g., https://somesite.org instead of https://somesite.org/ or https://somesite.org/geoserver). If the proxy base URL does not contain a path, adding a slash to the end of the URL will mitigate this vulnerability.
https://osgeo-org.atlassian.net/browse/GEOS-11867 https://github.com/geoserver/geoserver/pull/8622
org.geoserver.web:gs-web-app <= 2.26.3org.geoserver:gs-main <= 2.26.3org.geoserver:gs-main >= 2.27.0, <= 2.27.2org.geoserver.web:gs-web-app >= 2.27.0, <= 2.27.2Upgrade to a patched release:
org.geoserver.web:gs-web-app 2.26.4org.geoserver:gs-main 2.26.4org.geoserver:gs-main 2.27.3org.geoserver.web:gs-web-app 2.27.3Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21985Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server
CVE-2025-52465High· 7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device
CVE-2024-45747High· 7.2GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
CVE-2020-3577High· 7.4A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause…