CVE-2021-40822

HIGH EXPLOITED NUCLEI LAB

GeoServer <= 2.18.5 and 2.19.x <= 2.19.2 - Server-Side Request Forgery via Proxy Host Configuration

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-40822 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including phor3nsic. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a Python script to detect and verify the presence of CVE-2021-40822, an SSRF vulnerability in GeoServer. The script checks for GeoServer installation and tests for vulnerability by sending a crafted POST request.

Description

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Exploits (1)

nomisec SCANNER 2 stars
by phor3nsic · remote
https://github.com/phor3nsic/CVE-2021-40822

This repository contains a Python script to detect and verify the presence of CVE-2021-40822, an SSRF vulnerability in GeoServer. The script checks for GeoServer installation and tests for vulnerability by sending a crafted POST request.

Classification
Scanner 90%
Attack Type
Ssrf
Complexity
Trivial
Reliability
Reliable
Target: GeoServer
No auth needed
Prerequisites: Access to the target GeoServer instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Geoserver - Server-Side Request Forgery
HIGHVERIFIEDby For3stCo1d,aringo-bf
Shodan: title:"GeoServer" || http.title:"geoserver"
FOFA: app="GeoServer" || app="geoserver" || title="geoserver"

References (4)

Core 4
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/geoserver/geoserver/releases
Issue Tracking, Vendor Advisory x_refsource_misc
https://osgeo-org.atlassian.net/browse/GEOS-10229
Patch, Release Notes, Third Party Advisory x_refsource_confirm
https://github.com/geoserver/geoserver/compare/2.19.2...2.19.3
Issue Tracking, Vendor Advisory x_refsource_misc
https://osgeo-org.atlassian.net/browse/GEOS-10229?focusedCommentId=83508

Scores

CVSS v3 7.5
EPSS 0.9325
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Lab Environment

COMMUNITY SUSPICIOUS
Community Lab
docker pull geonode/geoserver

Details

VulnCheck KEV 2024-01-22
CWE
CWE-918
Status published
Products (2)
org.geoserver/gs-main 0Maven
osgeo/geoserver < 2.18.5
Published May 02, 2022
Tracked Since Feb 18, 2026