Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.geoserver/gs-wfs
  4. ›
  5. CVE-2025-30220

CVE-2025-30220: [XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service

June 10, 2025

GeoServer Web Feature Service (WFS) web service was found to be vulnerable to GeoTools CVE-2025-30220 XML External Entity (XXE) processing attack.

It is possible to trigger the parsing of external DTDs and entities, bypassing standard entity resolvers. This allows for Out-of-Band (OOB) data exfiltration of local files accessible by the GeoServer process, and Service Side Request Forgery (SSRF).

References

  • docs.geoserver.org/latest/en/user/production/config.html
  • github.com/advisories/GHSA-jj54-8f66-c5pc
  • github.com/geonetwork/core-geonetwork/pull/8757
  • github.com/geonetwork/core-geonetwork/pull/8803
  • github.com/geonetwork/core-geonetwork/pull/8812
  • github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc
  • github.com/geoserver/geoserver
  • github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc
  • github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw
  • nvd.nist.gov/vuln/detail/CVE-2025-30220

Code Behaviors & Features

Detect and mitigate CVE-2025-30220 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.25.7, all versions starting from 2.26.0 before 2.26.3, all versions starting from 2.27.0 before 2.27.1, version 2.27.0

Fixed versions

  • 2.27.1
  • 2.26.3
  • 2.25.7

Solution

Upgrade to versions 2.25.7, 2.26.3, 2.27.1 or above.

Impact 9.9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference
  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

maven/org.geoserver/gs-wfs/CVE-2025-30220.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:18:23 +0000.