← Vulnerability feed

Vulnerability record · CVE-2023-43795 · published 25 October 2023

CVE-2023-43795: GeoServer WPS server-side request forgery

Osgeo · Geoserver

GeoServer's OGC Web Processing Service (WPS) accepts GET and POST requests and does not adequately restrict the targets it fetches, allowing server-side request forgery. Because the service is network-reachable and needs no credentials, an unauthenticated attacker can make the server issue requests on their behalf. The flaw is patched in GeoServer 2.22.5 and 2.23.2.

9.8 CVSS 3.1 Critical EPSS 68% · top 0.7% CWE-918 · Server-side request forgery (SSRF)
9.8CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this a high-value target despite no KEV listing.

What it is

GeoServer's OGC Web Processing Service (WPS) accepts GET and POST requests and does not adequately restrict the targets it fetches, allowing server-side request forgery. Because the service is network-reachable and needs no credentials, an unauthenticated attacker can make the server issue requests on their behalf. The flaw is patched in GeoServer 2.22.5 and 2.23.2.

Impact

An attacker can force the GeoServer host to send requests to internal or external systems, reaching services that are not directly exposed and potentially reading internal resources or interacting with them under the server's identity. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the WPS endpoint using GET or POST requests; the CVSS vector shows no privileges and no user interaction required. Any deployment exposing WPS to untrusted networks is in scope.

Exploitation

Not listed in CISA KEV and no public exploit reference is provided, but EPSS is high at roughly 0.68 (99th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade GeoServer to 2.22.5 or 2.23.2, or a later release, as the primary fix.
  • If immediate upgrade is not possible, apply the vendor advisory's mitigation guidance for the WPS endpoint.
  • Restrict network access to the WPS endpoint to trusted clients and block outbound traffic from the GeoServer host to internal ranges.
  • Run GeoServer with least privilege so a forged request cannot reach sensitive internal services.
  • Monitor the vendor advisory for updated guidance.

Detection

  • Review GeoServer and proxy logs for WPS GET/POST requests containing external or internal URLs as parameters.
  • Alert on outbound connections from the GeoServer host to internal address ranges or unexpected destinations.
  • Baseline normal WPS request patterns and flag anomalous request volumes or targets.
  • Correlate GeoServer process network activity with HTTP request logs to spot SSRF-style fetches.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43795 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-25157GeoServer OGC filter SQL injection via CQL and PostGIS datastoreGeoServer supports the OGC Filter expression language and CQL through WFS, WMS and WCS, and mishandles certain filter constructs when a PostGIS datas…EPSS 85%analysed9.1CVE-2025-30220Geotools xml external entity (xxe) vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent…EPSS 42%8.2CVE-2025-58175Osgeo geoserver improper input validation vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…EPSS 0.47%8.2CVE-2024-29198Osgeo geoserver server-side request forgery (ssrf) vulnerabilityGeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side …EPSS 2.3%8.2CVE-2024-34711Osgeo geoserver information exposure vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …EPSS 0.30%7.5CVE-2025-30145Osgeo geoserver vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. Malicious Jiffle scripts can be executed by GeoServer, either…EPSS 0.51%7.5CVE-2024-38524Osgeo geoserver information exposure vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. org.geowebcache.GeoWebCacheDispatcher.handleFrontPage(HttpSer…EPSS 0.44%7.5CVE-2021-40822Osgeo geoserver server-side request forgery (ssrf) vulnerabilityGeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2023-43795), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.