XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
ID: 327701c0-8999-5c84-aaa1-1c28fe568226
STIX ID: report--327701c0-8999-5c84-aaa1-1c28fe568226
Feed Name: Kudelski Security
Threat Score
A high-severity XXE/SSRF vulnerability (CVE-2025-30220) in GeoServer WFS—caused by GeoTools improperly handling XML schema entity resolution—can enable out-of-band data exfiltration and server-side request forgery; multiple GeoServer versions are affected and users are advised to upgrade to patched releases, restrict WFS access, and monitor for suspicious XML/SSRF activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
