Vulnerability record · CVE-2023-43795 · published 25 October 2023
CVE-2023-43795: GeoServer WPS server-side request forgery
Osgeo · Geoserver
GeoServer's OGC Web Processing Service (WPS) accepts GET and POST requests and does not adequately restrict the targets it fetches, allowing server-side request forgery. Because the service is network-reachable and needs no credentials, an unauthenticated attacker can make the server issue requests on their behalf. The flaw is patched in GeoServer 2.22.5 and 2.23.2.
Description
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required and a high EPSS score make this a high-value target despite no KEV listing.
What it is
GeoServer's OGC Web Processing Service (WPS) accepts GET and POST requests and does not adequately restrict the targets it fetches, allowing server-side request forgery. Because the service is network-reachable and needs no credentials, an unauthenticated attacker can make the server issue requests on their behalf. The flaw is patched in GeoServer 2.22.5 and 2.23.2.
Impact
An attacker can force the GeoServer host to send requests to internal or external systems, reaching services that are not directly exposed and potentially reading internal resources or interacting with them under the server's identity. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the WPS endpoint using GET or POST requests; the CVSS vector shows no privileges and no user interaction required. Any deployment exposing WPS to untrusted networks is in scope.
Exploitation
Not listed in CISA KEV and no public exploit reference is provided, but EPSS is high at roughly 0.68 (99th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade GeoServer to 2.22.5 or 2.23.2, or a later release, as the primary fix.
- If immediate upgrade is not possible, apply the vendor advisory's mitigation guidance for the WPS endpoint.
- Restrict network access to the WPS endpoint to trusted clients and block outbound traffic from the GeoServer host to internal ranges.
- Run GeoServer with least privilege so a forged request cannot reach sensitive internal services.
- Monitor the vendor advisory for updated guidance.
Detection
- Review GeoServer and proxy logs for WPS GET/POST requests containing external or internal URLs as parameters.
- Alert on outbound connections from the GeoServer host to internal address ranges or unexpected destinations.
- Baseline normal WPS request patterns and flag anomalous request volumes or targets.
- Correlate GeoServer process network activity with HTTP request logs to spot SSRF-style fetches.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/geoserver/geoserver/security/advisories/GHSA-5pr3-m5hm-9956 | MitigationVendor Advisory |
| https://github.com/geoserver/geoserver/security/advisories/GHSA-5pr3-m5hm-9956 | MitigationVendor Advisory |
Track CVE-2023-43795 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-43795), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.