{"id":"GHSA-826p-4gcg-35vw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-826p-4gcg-35vw","summary":"GeoTools has XML External Entity (XXE) Processing Vulnerability in XSD schema handling","details":"### Summary\n\nGeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit.\n\n### Impact\n\nThis impacts whoever exposes XML processing with ``gt-xsd-core`` involved in parsing, when the documents carry a reference to an external XML schema. The ``gt-xsd-core`` Schemas class is not using the EntityResolver provided by the ParserHandler (if any was configured).\n\nThis also impacts users of ``gt-wfs-ng`` DataStore where the ENTITY_RESOLVER connection parameter was not being used as intended.\n\n### Resolution\n\nGeoTools API change allows EntityResolver to be supplied to the following methods:\n\n```java\nSchemas.parse( location, locators, resolvers, uriHandlers, entityResolver);\nSchemas.findSchemas(Configuration configuration, EntityResolver entityResolver);\n```\n\nWith this API change the `gt-wfs-ng` WFS DataStore ENTITY_RESOLVER parameter is now used.\n\n### Reference\n\n* [GHSA-jj54-8f66-c5pc](https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc): Describes the impact of the ``gt-xsd-core`` vulnerability on the GeoServer WFS protocol, resulting in both Service Side Request Forgery (SSRF) and Out-of-Band (OOB) data exfiltration of local files.\n\n* [GHSA-2p76-gc46-5fvc](https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc): Describes the impact of the ``gt-wfs-ng`` and ``gt-xsd-core`` vulnerability on the GeoNetwork WFS Index functionality.","published":"2025-06-09T23:14:48Z","modified":"2026-02-04T04:28:18.471515Z","cvss":{"score":9.9,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.geotools:gt-xsd-core","fixedVersion":"33.1"},{"ecosystem":"Maven","name":"org.geotools:gt-xsd-core","fixedVersion":"32.3"},{"ecosystem":"Maven","name":"org.geotools:gt-xsd-core","fixedVersion":"31.7"},{"ecosystem":"Maven","name":"org.geotools:gt-wfs-ng","fixedVersion":"33.1"},{"ecosystem":"Maven","name":"org.geotools:gt-wfs-ng","fixedVersion":"32.3"},{"ecosystem":"Maven","name":"org.geotools:gt-wfs-ng","fixedVersion":"31.7"},{"ecosystem":"Maven","name":"org.geotools:gt-xsd-core","fixedVersion":"28.6.1"},{"ecosystem":"Maven","name":"org.geotools:gt-wfs-ng","fixedVersion":"28.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-2p76-gc46-5fvc"},{"type":"WEB","url":"https://github.com/geoserver/geoserver/security/advisories/GHSA-jj54-8f66-c5pc"},{"type":"WEB","url":"https://github.com/geotools/geotools/security/advisories/GHSA-826p-4gcg-35vw"},{"type":"PACKAGE","url":"https://github.com/geotools/geotools"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T04:28:18.471515Z"}}