OSGeo (GeoServer) Data Breach

OSGeo (GeoServer) experienced a data breach that was reported on December 11, 2025. OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation

Key Facts

Organization
OSGeo (GeoServer)
Date Reported
December 11, 2025
Incident Type
unknown
Industry
Technology
Severity Score
5/10
Confidence Level
high

Source

View original source - External link to primary source documentation

Understanding unknown Incidents

Data breaches can result in significant financial, operational, and reputational damage. Organizations should implement defense-in-depth strategies and maintain incident response capabilities.