CVE-2025-58360CISA KEV: Actively Exploited

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

Published Dec 11, 2025·Updated Dec 11, 2025

Description

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.

Public Exploits & PoCs5 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free