Server-Side Request Forgery (SSRF) in geoserver - CVE-2021-40822
Published: May 5, 2026
geoserver
geoserver
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery (SSRF) in the TestWfsPost endpoint when handling user-supplied requests to specific targets. A remote attacker can send a specially crafted request to disclose sensitive information.
The issue is limited to specific targets, such as PHP + Nginx environments.