


Perceptive Security
SOC/SIEM Consultancy

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a speā¦
Published:
11 december 2025 om 00:00:00
Alert date:
11 december 2025 om 21:05:27
Source:
cisa.gov
OSGeo GeoServer contains an XML External Entity (XXE) vulnerability in the /geoserver/wms GetMap operation endpoint. The vulnerability allows attackers to define external entities within XML requests due to improper restriction of XML external entity references. This affects an open-source geospatial server component used across multiple products. The vulnerability could potentially allow attackers to access local files, perform server-side request forgery, or cause denial of service through malicious XML input processing.
Technical details
Mitigation steps:
Affected products:
OSGeo GeoServer
Related links:
https://osgeo-org.atlassian.net/browse/GEOS-11922
https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525
https://nvd.nist.gov/vuln/detail/CVE-2025-58360
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
