← Vulnerability feed

Vulnerability record · CVE-2025-58360 · published 25 November 2025

CVE-2025-58360: GeoServer WMS GetMap XXE allows unauthenticated file read and SSRF

Geoserver · Geoserver

GeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting external entity definitions. An attacker can submit crafted XML that defines external entities, triggering an XML External Entity (XXE) flaw. The issue is patched in 2.25.6, 2.26.3, and 2.27.0.

9.8 CVSS 3.1 Critical CISA KEV since 11 Dec 2025 EPSS 61% · top 0.9% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with a 2026-01-01 due date, and a 99.2nd percentile EPSS score indicate active exploitation and severe impact.

What it is

GeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting external entity definitions. An attacker can submit crafted XML that defines external entities, triggering an XML External Entity (XXE) flaw. The issue is patched in 2.25.6, 2.26.3, and 2.27.0.

Impact

Successful exploitation can expose local files and internal network resources reachable by the GeoServer process, and the CVSS vector rates confidentiality, integrity, and availability impact as high. An unauthenticated attacker gains a server-side request and file disclosure primitive.

Attack surface

Reachable over the network via the /geoserver/wms GetMap operation, which accepts XML input. The CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.

Exploitation

CVE-2025-58360 was added to CISA KEV on 2025-12-11 with a remediation due date of 2026-01-01, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.64874 (99.2nd percentile), and the vendor advisory is tagged Vendor Advisory.

What to do

  • Upgrade to GeoServer 2.25.6, 2.26.3, or 2.27.0 as applicable; these versions contain the fix.
  • If immediate patching is not possible, restrict network access to the /geoserver/wms endpoint to trusted clients only.
  • Disable external entity resolution in the XML parser or apply a WAF rule blocking external entity declarations in WMS GetMap requests.
  • Follow CISA KEV required actions and BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Detection

  • Monitor GeoServer and web server logs for POST or GET requests to /geoserver/wms with GetMap and XML bodies containing DOCTYPE or ENTITY declarations.
  • Alert on outbound network connections from the GeoServer host to unexpected internal or external hosts, which may indicate XXE-based SSRF.
  • Review file access and process telemetry on the GeoServer host for reads of sensitive local files by the Java process.
  • Correlate requests to /geoserver/wms with anomalous response sizes or error patterns that may indicate entity expansion.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-58360 to the Known Exploited Vulnerabilities catalog on 11 December 2025 as "OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 January 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-58360 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-36401GeoServer OGC request parameter XPath eval injection enables unauthenticated RCEGeoServer versions before 2.22.6, 2.23.6, 2.24.4, and 2.25.2 unsafely evaluate OGC request parameters as XPath expressions via the GeoTools commons-j…KEVEPSS 100%analysed9.8CVE-2023-35042Geoserver vulnerabilityGeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData wit…EPSS 43%7.5CVE-2024-24749Geoserver path traversal vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed…EPSS 0.76%7.2CVE-2023-41877Geoserver path traversal vulnerabilityGeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in ve…EPSS 0.84%7.2CVE-2023-51444Geoserver improper input validation vulnerabilityGeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerabili…EPSS 1.9%6.1CVE-2025-21621Geoserver cross-site scripting vulnerabilityGeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a reflected cross-site scripting (XS…EPSS 0.30%6.0CVE-2024-23634Geoserver improper input validation vulnerabilityGeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file renaming vulnerabi…EPSS 0.69%5.0CVE-2008-7227Geoserver memory buffer overflow vulnerabilityPartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer,…EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2025-58360), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.