
`GeoNetwork` (via `GeoTools`, `GeoServer`) has an XXE vulnerability (CVE-2025-30220) in XSD handling. This could permit information disclosure or SSRF. #XXE #GeoNetwork #infosec https://www.pulsepatch.io/posts/cve-2025-30220-geonetwork-xxe-vulnerability
Post summary
The post announces CVE‑2025‑30220, an XXE vulnerability in GeoNetwork via GeoTools/GeoServer that can enable information disclosure or SSRF. No PoC, exploit, active use, or patch is disclosed.
