GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=<url>`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the use of dynamic styles, without also configuring URL checks, provides the opportunity for Service Side Request Forgery. This vulnerability can be used to steal user NetNTLMv2 hashes which could be relayed or cracked externally to gain further access. This vulnerability has been patched in versions 2.22.5 and 2.23.2.
Use CWE-918, Osgeo vendor hub and Geoserver product page to widen CVE-2023-41339 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-30220, CVE-2023-25157 and CVE-2024-34711 for nearby disclosures in the same product family.