S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 17, 2025

CVE-2025-30220 Scanner

CVE-2025-30220 Scanner - XML External Entity (XXE) vulnerability in GeoServer

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-30220
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
geoserverby geoserver
>= 2.27.0, < 2.27.1
Updated Aug 22, 2026View on NVD →
Detail

GeoServer is an open-source server that allows users to share, process, and edit geospatial data. It is used by governments, companies, and research institutions worldwide for robust and flexible geographic data server functionality. It supports a variety of data formats and is compatible with popular geospatial client applications like OpenLayers and Google Earth. GeoServer boasts a presentation layer converting data into images like JPEGs or PNGs for maps. As one of the most popular geospatial web services, it's essential for managing complex geospatial information across multiple sectors. Designed to integrate seamlessly with various data systems, GeoServer stands at the forefront of geographic information system solutions.

The XML External Entity (XXE) vulnerability is a type of security flaw that arises from the application processing XML input from an untrusted source using weakly configured XML parsers. Attackers can exploit this flaw in GeoServer by sending malicious XML content. This vulnerability allows for the exposure of sensitive server-side files and interaction with external servers. Exploiting XXE can lead to severe impacts such as denial of service, information disclosure, and server shutdowns. It's a critical risk, particularly in systems that depend heavily on XML files for data interchange. With increasingly sophisticated attack techniques, XXE remains a high-priority vulnerability to address in GeoServer installations.

The vulnerability in GeoServer occurs due to improper XML input handling in its Web Feature Service (WFS). When malformed XML is processed, external entities can be misused to cause Out-of-Band (OOB) data extraction or assert Server-Side Request Forgery (SSRF). This is achieved through crafted requests directed to the GeoTools library within GeoServer. Attackers can manipulate these requests to achieve unintended interactions with external systems. GeoServer's insufficient isolation of XML processing mechanics compounds the problem, making its interfaces susceptible to XXE. The principal risk lies within WFS calls, whereby inclusive malicious payloads could exploit system weaknesses.

If exploited by adversaries, this XXE vulnerability allows unauthorized access to back-end server data, risking the compromise of confidential information. Attackers may disclose file contents or perform arbitrary file writes, potentially leading to data theft. The associated SSRF aspect can facilitate further attacks against neighboring infrastructure. Beyond information leaks, exploiting this vulnerability can result in service disruption or denial, impeding genuine users' access to geospatial data services. Overall, the scale of potential violation ranges from minor service impediments to significant data breach incidents, urging high caution for GeoServer administrators.

REFERENCES

Solution Advice
  • Update GeoServer to the latest version that has patched this vulnerability.
  • Disable XML External Entity (XXE) processing in the XML parser configuration.
  • Implement input validation to sanitize and verify incoming XML data before processing.
  • Monitor server logs for unusual access patterns that may indicate exploitation attempts.
  • Conduct regular security audits and penetration testing on the server and its services.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.