CVE-2025-58360 is a critical XML External Entity (XXE) vulnerability (CWE-611) affecting GeoServer versions 2.26.0 up to 2.26.2 and before 2.25.6. This flaw allows an unauthenticated attacker to define external entities via a crafted XML request to the /geoserver/wms GetMap endpoint, leading to severe impacts. With a CVSS score of 9.8 (CRITICAL), the vulnerability is easily exploitable over the network with no user interaction, potentially resulting in full compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has publicly available exploit modules in Metasploit and Nuclei, garnering significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.25.6CPE matchmatch criteria | cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:* | ||
>= 2.26.0, < 2.26.2CPE matchmatch criteria | cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.