top of page
perceptive_background_267k.jpg

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a spe…

Published:

11 december 2025 om 00:00:00

Alert date:

11 december 2025 om 21:05:27

Source:

cisa.gov

Click to open the original link from this advisory

OSGeo GeoServer contains an XML External Entity (XXE) vulnerability in the /geoserver/wms GetMap operation endpoint. The vulnerability allows attackers to define external entities within XML requests due to improper restriction of XML external entity references. This affects an open-source geospatial server component used across multiple products. The vulnerability could potentially allow attackers to access local files, perform server-side request forgery, or cause denial of service through malicious XML input processing.

Technical details

Mitigation steps:

Affected products:

OSGeo GeoServer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page