CVE-2025-30220

CRITICAL

CVSS v3

9.9

CRITICAL

EPSS Score

13.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also imp

Technical Details

CVSS v3 Vector
3.1
Published
6/10/2025
Last Modified
8/26/2025

Frequently Asked Questions

What is CVE-2025-30220?

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured). This also imp

Is CVE-2025-30220 actively exploited?

Active exploitation of CVE-2025-30220 has not been confirmed. The EPSS score is 13.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-30220?

CVE-2025-30220 has a CVSS v3 base score of 9.9 (CRITICAL severity), with vector string 3.1.

Is CVE-2025-30220 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.