Advisories for Maven/Org.geoserver/Gs-Wfs package

2025

[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service

GeoServer Web Feature Service (WFS) web service was found to be vulnerable to GeoTools CVE-2025-30220 XML External Entity (XXE) processing attack. It is possible to trigger the parsing of external DTDs and entities, bypassing standard entity resolvers. This allows for Out-of-Band (OOB) data exfiltration of local files accessible by the GeoServer process, and Service Side Request Forgery (SSRF).

2024
2023