geoserver Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for geoserver products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
7
In CISA KEV
2
Beyond CISA KEV
5
Sensor Observed
0
Virtual Patch Available
0
geoserver KEVs Added by Year
7 geoserver KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-27505
GeoServer Missing Authorization on REST API Index |
geoserver | High | Not in CISA | 20 Nov 2025 |
|
CVE-2025-30220
GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling |
geoserver | High | Not in CISA | 02 Aug 2025 |
|
CVE-2025-58360
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature |
geoserver | Confirmed | In CISA | 30 May 2026 |
|
CVE-2023-35042
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData... |
GeoServer | High | Not in CISA | 12 Jun 2023 |
|
CVE-2021-40822
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. |
GeoServer | High | Not in CISA | 26 Apr 2025 |
|
CVE-2023-43795
WPS Server Side Request Forgery in GeoServer |
geoserver | High | Not in CISA | 26 Apr 2025 |
|
CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver |
geoserver | Confirmed | In CISA | 15 Jul 2024 |
Common Vulnerability Classes (CWE)
- CWE-918 — Server-Side Request Forgery (SSRF) 3
- CWE-611 — Improper Restriction of XML External Entity Reference 2
- CWE-862 — Missing Authorization 1
- CWE-95 — Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology