Vulnerability record · CVE-2025-58360 · published 25 November 2025
CVE-2025-58360: GeoServer WMS GetMap XXE allows unauthenticated file read and SSRF
Geoserver · Geoserver
GeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting external entity definitions. An attacker can submit crafted XML that defines external entities, triggering an XML External Entity (XXE) flaw. The issue is patched in 2.25.6, 2.26.3, and 2.27.0.
Description
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with a 2026-01-01 due date, and a 99.2nd percentile EPSS score indicate active exploitation and severe impact.
What it is
GeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting external entity definitions. An attacker can submit crafted XML that defines external entities, triggering an XML External Entity (XXE) flaw. The issue is patched in 2.25.6, 2.26.3, and 2.27.0.
Impact
Successful exploitation can expose local files and internal network resources reachable by the GeoServer process, and the CVSS vector rates confidentiality, integrity, and availability impact as high. An unauthenticated attacker gains a server-side request and file disclosure primitive.
Attack surface
Reachable over the network via the /geoserver/wms GetMap operation, which accepts XML input. The CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.
Exploitation
CVE-2025-58360 was added to CISA KEV on 2025-12-11 with a remediation due date of 2026-01-01, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.64874 (99.2nd percentile), and the vendor advisory is tagged Vendor Advisory.
What to do
- Upgrade to GeoServer 2.25.6, 2.26.3, or 2.27.0 as applicable; these versions contain the fix.
- If immediate patching is not possible, restrict network access to the /geoserver/wms endpoint to trusted clients only.
- Disable external entity resolution in the XML parser or apply a WAF rule blocking external entity declarations in WMS GetMap requests.
- Follow CISA KEV required actions and BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor GeoServer and web server logs for POST or GET requests to /geoserver/wms with GetMap and XML bodies containing DOCTYPE or ENTITY declarations.
- Alert on outbound network connections from the GeoServer host to unexpected internal or external hosts, which may indicate XXE-based SSRF.
- Review file access and process telemetry on the GeoServer host for reads of sensitive local files by the Java process.
- Correlate requests to /geoserver/wms with anomalous response sizes or error patterns that may indicate entity expansion.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-58360 to the Known Exploited Vulnerabilities catalog on 11 December 2025 as "OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 January 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525 | Vendor Advisory |
| https://osgeo-org.atlassian.net/browse/GEOS-11682 | Issue Tracking |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-58360 | US Government Resource |
Track CVE-2025-58360 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-58360), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.