GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XSS) vulnerability exists in the WMS GetFeatureInfo HTML output format that enables a remote attacker to execute arbitrary JavaScript code in a victim's browser through specially crafted SLD_BODY parameters. This issue has been patched in version 2.25.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-79"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21621.json"
}{
"cpe": "cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.25.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21621.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"304143921670282980344165642834298034385",
"69425362178033528593940703493127584809",
"61581086786685673862882248908854167088",
"192920088757599760416120378948530642714",
"240832705630790953029570445138883683749",
"208293811668401471830488450298961494331",
"339810986985387919392014410702078517272",
"183643863772292226796229508880572084658",
"265508811185593093288067607100366029325",
"283983633182392005647995609671899455028",
"289623306617053730666568647858173412159",
"36414781463002635162671122812121510244",
"150082061794064175532556469463654880870",
"290640940200560937506480662058605177222",
"126359404159835560919522246053236138446",
"130216415808421990729810051238126307357",
"259703568808090652397710696170960914372",
"116465866168401548155513235915268850291",
"60411145620372664215350091930395726580",
"308880315474470337214973885477032069450",
"270218511811788907423793502736519301383",
"217904410638450578415198349202197919520",
"310191035584785380202977115545597652471",
"259782448837144607068942274498368253814",
"98651410200881163305868947844222380895"
],
"threshold": 0.9
},
"id": "CVE-2025-21621-0d20b4b2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/dc9ff1c726dd73c884437a123b4ad72b19383c7d",
"target": {
"file": "src/wms/src/test/java/org/geoserver/wms/featureinfo/HTMLFeatureInfoOutputFormatTest.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"325726358613099458862193558113761225184",
"326724414226326793091402809624040308759",
"300558453433719580123825628169805957325",
"259310657788014039438730385768290134575",
"92683004693753593881687826396647101794",
"10556451985284442405850329125017121348",
"99783030236360265685130620643536528416",
"155044097411897404876165721848872512974"
],
"threshold": 0.9
},
"id": "CVE-2025-21621-5a546fe2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/dc9ff1c726dd73c884437a123b4ad72b19383c7d",
"target": {
"file": "src/wms/src/main/java/org/geoserver/wms/featureinfo/FreeMarkerTemplateManager.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "101730600859228701056700742042750452769",
"length": 652
},
"id": "CVE-2025-21621-97edf068",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/dc9ff1c726dd73c884437a123b4ad72b19383c7d",
"target": {
"file": "src/wms/src/main/java/org/geoserver/wms/featureinfo/FreeMarkerTemplateManager.java",
"function": "getTemplate"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "238160103101791286773899863303668683907",
"length": 973
},
"id": "CVE-2025-21621-e78eaed4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/geoserver/geoserver/commit/dc9ff1c726dd73c884437a123b4ad72b19383c7d",
"target": {
"file": "src/wms/src/test/java/org/geoserver/wms/featureinfo/HTMLFeatureInfoOutputFormatTest.java",
"function": "testAutoEscaping"
}
}
]
"2026-08-12T14:52:30Z"