Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x4r9-gmw3-hxww | GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution |
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Geoserver
Geoserver geoserver |
|
| Vendors & Products |
Geoserver
Geoserver geoserver |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `ENTITY_RESOLUTION_ALLOWLIST` may allow attacker to perform unauthenticated Server-Side Request Forgery (SSRF). This vulnerability requires that GeoServer is set up to use a proxy base URL and the `ENTITY_RESOLUTION_ALLOWLIST` (default since 2.25.0). Versions 2.26.4 and 2.27.3 contain a fix. GeoServer installations are only affected by this vulnerability if they use a proxy base URL that does not contain a URL path or end with a slash. If the proxy base URL does not contain a path, adding a slash to the end of the URL will mitigate this vulnerability. | |
| Title | GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution | |
| Weaknesses | CWE-20 CWE-611 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T15:26:07.311Z
Reserved: 2025-08-27T13:34:56.189Z
Link: CVE-2025-58175
Updated: 2026-06-18T15:26:03.717Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:55:59Z
Github GHSA