EIP-2026-104261
PRE-CVEGeoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
Title source: legacyDescription
Geoserver < 2.7.1.1 / < 2.6.4 / < 2.5.5.1 - XML External Entity
Exploits (1)
exploitdb
WORKING POC
by David Bloom · pythonwebappsmultiple
https://www.exploit-db.com/exploits/37757
Details
Status
pre_cve
Tracked Since
Feb 18, 2026