Server-Side Request Forgery (SSRF) in geoserver - CVE-2024-40625
Published: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to server-side request forgery in the Coverage REST API endpoint /workspaces/{workspaceName}/coveragestores/{storeName}/{method}.{format} when handling file uploads by URL with the method set to url. A remote privileged user can supply a crafted URL to perform server-side request forgery.
The issue is in RESTUtils.java, and no user interaction is required.