PT-2026-49054 · Git+3 · Geoserver+2
CVE-2025-58175
·
Published
2026-06-12
·
Updated
2026-06-18
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
GeoServer versions prior to 2.26.4
GeoServer versions prior to 2.27.3
Description
GeoServer allows unauthenticated Server-Side Request Forgery (SSRF), a condition where an attacker can cause the server to make requests to an unintended location. This occurs when the server is configured to use a proxy base URL and the
ENTITY RESOLUTION ALLOWLIST. The issue specifically affects installations where the proxy base URL does not contain a URL path or does not end with a slash.Recommendations
Update to version 2.26.4.
Update to version 2.27.3.
If the proxy base URL does not contain a path, add a slash to the end of the URL to mitigate the risk.
Exploit
Fix
XXE
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Geoserver
Org.Geoserver.Web:Gs-Web-App
Org.Geoserver:Gs-Main