U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-30220

Change History

New CVE Received from GitHub, Inc. 6/10/2025 12:15:37 PM

Action Type Old Value New Value
Added Description

								
							
							
						
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also impacts users of gt-wfs-ng DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended. This vulnerability is fixed in GeoTools 33.1, 32.3, 31.7, and 28.6.1, GeoServer 2.27.1, 2.26.3, and 2.25.7, and GeoNetwork 4.4.8 and 4.2.13.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Added CWE

								
							
							
						
CWE-611
Added CWE

								
							
							
						
CWE-918
Added Reference

								
							
							
						
https://docs.geoserver.org/latest/en/user/production/config.html#production-config-external-entities
Added Reference

								
							
							
						
https://github.com/geonetwork/core-geonetwork/pull/8757
Added Reference

								
							
							
						
https://github.com/geonetwork/core-geonetwork/pull/8803
Added Reference

								
							
							
						
https://github.com/geonetwork/core-geonetwork/pull/8812
Added Reference

								
							
							
						
https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc
Added Reference

								
							
							
						
https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc
Added Reference

								
							
							
						
https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw