CVE-2025-58360
OSGeo GeoServer: Improper Restriction of XML External Entity Reference
As of , CVE-2025-58360 in OSGeo GeoServer is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 11 December 2025
- US federal deadline
- 1 January 202621 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.61Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: github.com and osgeo-org.atlassian.netLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA's required action
- github.comThis vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information…
- osgeo-org.atlassian.net
What the flaw is
OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.
CISA's description
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.
The CVE record's description, from GitHub_M
- CVE published
- 25 November 2025
- Assigned by
- GitHub_M
- CVSS
- 8.2 High (CVSS 3.1, from the CNA)
- CWE-611
- Improper Restriction of XML External Entity Reference
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: GeoServer WMS GetMap XXE Arbitrary File Readauxiliary module, rank normal
GeoServer: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-36401GeoTools Eval Injection | OSGeo GeoServer | Patch this weekMetasploit module; EPSS 0.99 | 0.99 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org