PT-2025-48086 · Geoserver · Geoserver

Published

2025-11-25

·

Updated

2025-11-29

·

CVE-2025-58360

CVSS v2.0
8.5
VectorAV:N/AC:L/Au:N/C:C/I:N/A:P
Name of the Vulnerable Software and Affected Versions GeoServer versions 2.26.0 through 2.26.1 and versions prior to 2.25.6
Description GeoServer is an open-source server used for sharing and editing geospatial data. A flaw exists in the way the software handles XML input received through the
/geoserver/wms
GetMap
operation. Insufficient sanitization of this input allows attackers to define external entities within XML requests, leading to an XML External Entity (XXE) condition. This can enable an attacker to read arbitrary files from the server's file system, conduct Server-Side Request Forgery (SSRF), or execute Denial of Service (DoS) attacks. Approximately 49.4k instances are reportedly exposed.
Recommendations Update to GeoServer version 2.25.6, 2.26.3, or 2.27.0.

Fix

XXE

Weakness Enumeration

Related Identifiers

BDU:2025-14710
CVE-2025-58360
GHSA-FJF5-XGMQ-5525

Affected Products

Geoserver