← Back to browse · API

CVE-2025-58360

Severity
HIGH
CVSS
8.2
EPSS
0.64874
Risk score
80.51
CISA KEV
Yes
PoC
No
Published
2025-12-11
Modified
2025-12-11
First seen
2026-08-07
Aliases
EUVD-2025-199606, GHSA-FJF5-XGMQ-5525
Products
OSGeo:GeoServer, geoserver:geoserver 2.26.0, < 2.26.2, geoserver:geoserver < 2.25.6
Sources
euvd EUVD-2025-199606
cisa.gov CVE-2025-58360

Description

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.

References