XML External Entity injection in geoserver - CVE-2025-30220
Published: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote attacker to disclose sensitive information and perform server-side request forgery.
The vulnerability exists due to improper restriction of xml external entity reference in the WFS service XSD schema handling when parsing XML requests. A remote attacker can send a specially crafted XML request to disclose sensitive information and perform server-side request forgery.
The issue bypasses the standard entity resolver and can trigger parsing of external DTDs and entities.