logo

XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service

ID: 327701c0-8999-5c84-aaa1-1c28fe568226

STIX ID: report--327701c0-8999-5c84-aaa1-1c28fe568226

Feed Name: Kudelski Security

Threat Score
70/100

Date Published: 2025-06-19

Date Updated: 2026-07-22

...
...

A high-severity XXE/SSRF vulnerability (CVE-2025-30220) in GeoServer WFS—caused by GeoTools improperly handling XML schema entity resolution—can enable out-of-band data exfiltration and server-side request forgery; multiple GeoServer versions are affected and users are advised to upgrade to patched releases, restrict WFS access, and monitor for suspicious XML/SSRF activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.