Maven package intelligence

org.geoserver:gs-main Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.geoserver:gs-main, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.geoserver:gs-main
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.geoserver:gs-main KEVs with sensor-observed exploitation activity

Review org.geoserver:gs-main exploitation against the versions you run

One of the one exploited org.geoserver:gs-main vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested org.geoserver:gs-main vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2021-40822

GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

Beyond CISA 26 Apr 2025

Recurring weakness patterns

Server-Side Request Forgery (SSRF) account for mapped occurrences across this org.geoserver:gs-main KEV portfolio.

Browse all KEVs →