EXPOSURES › CVE-2025-58360
CVE-2025-58360
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatched
GeoServer exposed to XML external entity attacks
OSGeo's GeoServer, a mapping server, allowed attackers to exploit an improper restriction of XML external entity reference vulnerability through its /geoserver/wms/GetMap endpoint, enabling remote code execution.
Shame score — Known exploitation indicates negligence in security updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.