References https://nvd.nist.gov/vuln/detail/CVE-2024-29198 https://github.com/geoserver/geoserver/security/advisories/GHSA-5gw5-jccf-6hxw https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-29198.yaml https://geoserver.org/vulnerability/2025/06/10/cve-disclosure.html https://advisories.gitlab.com/maven/org.geoserver.web/gs-app/CVE-2024-29198/ https://hossted.com/knowledge-base/newsflash/data-management-and-analytics/database/geoserver-ssrf-via-demo-request-endpoint-when-proxy-base-url-is-unset/ https://cve.imfht.com/detail/CVE-2024-29198 https://stack.chaitin.com/vuldb/detail/76797280-4403-4c06-b1b5-6a7dac7037ae https://geoserver.org/announcements/vulnerability/2024/06/18/geoserver-2-25-2-released.html https://s4e.io/tools/geoserver-demo-request-endpoint-ssrf-cve-2024-29198
Related VulnerabilitiesPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCCVE-2026-20896: Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication BypassPoCCVE-2025-26399: SolarWinds Web Help Desk < 12.8.7 - AjaxProxy Deserialization RCEPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionGeoServer jsonArrayContains SQL注入漏洞LobeChat /webapi/proxy 服务器端请求伪造漏洞(CVE-2026-54157)东胜物流软件 /PriceCarrier/CrmProxyMailListHtmlGridSource.aspx SQL 注入漏洞关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告GeoServer /geoserver/wms 服务器端请求伪造漏洞(CVE-2023-43795)Apache Druid /proxy/coordinator@ 服务器端请求伪造漏洞(CVE-2025-27888)Gradio /proxy 服务器端请求伪造漏洞(CVE-2023-34239)GeoServer /geoserver/topp/wfs 代码执行漏洞