CVE-2025-58175
GeoServer is an open source server that allows users to share and edit geospatial data.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF). This vulnerability requires that GeoServer is set up to use a proxy base URL and the `ENTITY_RESOLUTION_ALLOWLIST` (default since 2.25.0). Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations are only affected by this vulnerability if they use a proxy base URL that does not contain a URL path or end with a slash. If the proxy base URL does not contain a path, adding a slash to the end of the URL will mitigate this vulnerability.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
- EPSS
- 0.47% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-611, CWE-918
- Affected
- osgeo/geoserver
- Source
- security-advisories@github.com
References
- https://github.com/geoserver/geoserver/pull/8622Issue Tracking, Patch
- https://github.com/geoserver/geoserver/security/advisories/GHSA-x4r9-gmw3-hxwwMitigation, Vendor Advisory
- https://osgeo-org.atlassian.net/browse/GEOS-11867Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.