Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

GeoServer XML External Entity Vulnerability in WMS GetMap Operation

Vulnerability

A vulnerability allowing XML External Entity (XXE) attacks has been identified in GeoServer versions 2.26.0 prior to 2.26.2 and versions prior to 2.25.6. This vulnerability arises because the application accepts XML input through the WMS GetMap operation without adequate sanitization. As a result, an attacker can exploit this flaw by defining external entities in the XML request, potentially leading to the disclosure of sensitive information, denial-of-service conditions, or unauthorized interactions with internal systems.

Impact

Exploitation of this vulnerability allows attackers to read arbitrary files from the server, conduct Server-Side Request Forgery (SSRF) attacks, and execute denial-of-service attacks by exhausting server resources.

Remediation

Users are advised to update GeoServer to version 2.25.6, 2.26.3, or 2.27.0.

Added: Nov 25, 2025, 9:18 PM
Updated: Dec 11, 2025, 8:03 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.6
exploitability
9.8
remediation
7.7
relevance
1.1
threat
9.6
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.