PT-2026-49054 · Git+3 · Geoserver+2

CVE-2025-58175

·

Published

2026-06-12

·

Updated

2026-06-18

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions GeoServer versions prior to 2.26.4 GeoServer versions prior to 2.27.3
Description GeoServer allows unauthenticated Server-Side Request Forgery (SSRF), a condition where an attacker can cause the server to make requests to an unintended location. This occurs when the server is configured to use a proxy base URL and the ENTITY RESOLUTION ALLOWLIST. The issue specifically affects installations where the proxy base URL does not contain a URL path or does not end with a slash.
Recommendations Update to version 2.26.4. Update to version 2.27.3. If the proxy base URL does not contain a path, add a slash to the end of the URL to mitigate the risk.

Exploit

Fix

XXE

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58175
GHSA-X4R9-GMW3-HXWW

Affected Products

Geoserver
Org.Geoserver.Web:Gs-Web-App
Org.Geoserver:Gs-Main