cve-2025-30220

CRITICAL CVSS 9.9 opencve
Description

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.

Timeline
Published
2025-06-10 16:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L mitre
3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L nvd
3.1 9.9 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "EUVD-2025-17683",
      "source": "euvd",
      "title": "[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-17683"
    },
    {
      "id": "GHSA-jj54-8f66-c5pc",
      "source": "ghsa",
      "title": "[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service",
      "url": "https://github.com/advisories/GHSA-jj54-8f66-c5pc"
    }
  ],
  "cve": "CVE-2025-30220",
  "enrichment": {
    "created": "2025-06-27T14:10:58.861665+00:00",
    "updated": "2025-06-27T14:10:58.861729+00:00",
    "vendors": [
      "geonetwork",
      "geonetwork$PRODUCT$opensource",
      "geonetwork-opensource",
      "geonetwork-opensource$PRODUCT$geonetwork",
      "geoserver",
      "geoserver$PRODUCT$geoserver",
      "geotools",
      "geotools$PRODUCT$geotools"
    ]
  },
  "epss": {
    "score": 0.42285
  },
  "mitre": {
    "cpes": [],
    "created": "2025-06-10T15:16:39.339000+00:00",
    "description": "GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.9,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2025/30xxx/CVE-2025-30220.json",
    "references": [
      "https://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities",
      "https://github.com/geonetwork/core-geonetwork/pull/8757",
      "https://github.com/geonetwork/core-geonetwork/pull/8803",
      "https://github.com/geonetwork/core-geonetwork/pull/8812",
      "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc",
      "https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc",
      "https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw"
    ],
    "title": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling",
    "updated": "2025-06-10T17:13:09.180000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-611",
      "CWE-918"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:*",
      "cpe:2.3:a:geotools:geotools:33.0:*:*:*:*:*:*:*",
      "cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*",
      "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
      "cpe:2.3:a:osgeo:geoserver:2.27.0:*:*:*:*:*:*:*"
    ],
    "created": "2025-06-10T16:15:37.387000+00:00",
    "description": "GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 9.9,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2025/CVE-2025-30220.json",
    "references": [
      "https://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities",
      "https://github.com/geonetwork/core-geonetwork/pull/8757",
      "https://github.com/geonetwork/core-geonetwork/pull/8803",
      "https://github.com/geonetwork/core-geonetwork/pull/8812",
      "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc",
      "https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc",
      "https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw"
    ],
    "title": null,
    "updated": "2026-06-17T09:08:22.870000+00:00",
    "vendors": [
      "geotools",
      "geotools$PRODUCT$geotools",
      "osgeo",
      "osgeo$PRODUCT$geonetwork",
      "osgeo$PRODUCT$geoserver"
    ],
    "weaknesses": [
      "CWE-611",
      "CWE-918"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-06-10T15:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-611",
                "CWE-918"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities",
                "https://github.com/geonetwork/core-geonetwork/pull/8757",
                "https://github.com/geonetwork/core-geonetwork/pull/8803",
                "https://github.com/geonetwork/core-geonetwork/pull/8812",
                "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc",
                "https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc",
                "https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 9.9,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "d99ac3b0-802a-444d-bc39-5392f1b8f0e5"
      },
      {
        "created": "2025-06-10T18:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "5c87857a-2d7a-45dc-90d2-6607533ce2fe"
      },
      {
        "created": "2025-07-12T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.05835
                  },
                  "old": {
                    "score": 0.05388
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "9ca34b80-fad5-48ce-a3ef-a04d2f6e1322"
      },
      {
        "created": "2025-07-16T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.08174
                  },
                  "old": {
                    "score": 0.05835
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "88ea354d-4c02-46be-9c1a-fe9fd740d089"
      },
      {
        "created": "2025-08-26T16:15:00+00:00",
        "data": [
          {
            "details": [
              "osgeo",
              "osgeo$PRODUCT$geonetwork",
              "osgeo$PRODUCT$geoserver"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:*",
                "cpe:2.3:a:geotools:geotools:33.0:*:*:*:*:*:*:*",
                "cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*",
                "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "cpe:2.3:a:osgeo:geoserver:2.27.0:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "osgeo",
                "osgeo$PRODUCT$geonetwork",
                "osgeo$PRODUCT$geoserver"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "b84571ba-a513-49a4-8e3f-9ec947be96f8"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:geotools:geotools:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:geotools:geotools:33.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:osgeo:geonetwork:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:osgeo:geoserver:2.27.0:*:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2025-06-10T15:16:39.339000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 9.9,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.42285
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities",
        "https://github.com/geonetwork/core-geonetwork/pull/8757",
        "https://github.com/geonetwork/core-geonetwork/pull/8803",
        "https://github.com/geonetwork/core-geonetwork/pull/8812",
        "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc",
        "https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc",
        "https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling",
      "provider": "mitre"
    },
    "updated": {
      "data": "2025-08-26T16:10:11.830000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "geonetwork",
        "geonetwork$PRODUCT$opensource",
        "geonetwork-opensource",
        "geonetwork-opensource$PRODUCT$geonetwork",
        "geoserver",
        "geoserver$PRODUCT$geoserver",
        "geotools",
        "geotools$PRODUCT$geotools",
        "osgeo",
        "osgeo$PRODUCT$geonetwork",
        "osgeo$PRODUCT$geoserver"
      ],
      "providers": [
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-611",
        "CWE-918"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-06-10T15:16:39.339000+00:00",
    "description": "GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling",
    "updated": "2025-06-10T17:13:05.703000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/30xxx/CVE-2025-30220.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON