GeoServer Web Feature Service (WFS) is vulnerable to an XML External Entity (XXE) processing attack due to improper handling of XML input. This vulnerability allows attackers to perform Out-of-Band (OOB) data exfiltration and Server-Side Request Forgery (SSRF) by exploiting the GeoTools library.
id: CVE-2025-30220
info:
name: GeoServer WFS - XXE Processing Vulnerability
author: iamnoooob,p
...