Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-58360
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H N L 8.2 .6052 99.1 YES
AFFECTED
Product Versions Fixed
geoserver >= 2.26.0, < 2.26.2 – —
TIMELINE
Aug 29 Reserved by GitHub_M
Nov 25 Published (CNA: GitHub_M)
Dec 11 Added to CISA KEV, remediation due 2026-01-01
Description
GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 29, 2025 | Reserved | Reserved by GitHub_M |
| November 25, 2025 | Published | Published (CNA: GitHub_M) |
| December 11, 2025 | KEV ADDED | Added to CISA KEV, remediation due 2026-01-01 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| geoserver | geoserver | — | >= 2.26.0, < 2.26.2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-58360 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.