CVE-2025-58360

HIGH KEV NUCLEI LAB

GeoServer WMS GetMap XXE Arbitrary File Read

Title source: metasploit

Description

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request. This issue has been patched in GeoServer 2.25.6, GeoServer 2.26.3, and GeoServer 2.27.0.

Exploits (8)

nomisec WORKING POC 4 stars
by quyenheu · infoleak
https://github.com/quyenheu/CVE-2025-58360
nomisec WORKING POC 1 stars
by thomas-osgood · infoleak
https://github.com/thomas-osgood/cve-2025-58360
nomisec WRITEUP
by quyenheu · poc
https://github.com/quyenheu/Bypass-CVE-2025-58360
nomisec WORKING POC
by Joker-Wiggin · infoleak
https://github.com/Joker-Wiggin/CVE-2025-58360-GeoServer-XXE
nomisec SCANNER
by rxerium · poc
https://github.com/rxerium/CVE-2025-58360
nomisec WRITEUP
by carlzhang123 · poc
https://github.com/carlzhang123/Blackash-CVE-2025-58360
metasploit WORKING POC
by xbow-security · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/geoserver_wms_getmap_xxe_file_read.rb

Nuclei Templates (1)

GeoServer - XML External Entity Injection
HIGHVERIFIEDby lbb,xbow,darses
Shodan: title:"geoserver" || http.html_hash:1093634893 "Content-Disposition: inline" || http.favicon.hash:97540678 || html:"/geoserver/"
FOFA: title="geoserver" || app="geoserver" || icon_hash="97540678" || body="/geoserver/"

Scores

CVSS v3 8.2
EPSS 0.8351
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Lab Environment

COMMUNITY
Community Lab
docker pull docker.osgeo.org/geoserver:2.25.5
docker pull docker.osgeo.org/geoserver:2.27.0
+4 more repos

Details

CISA KEV 2025-12-11
VulnCheck KEV 2025-12-05
ENISA EUVD EUVD-2025-199606
CWE
CWE-611
Status published
Products (3)
geoserver/geoserver < 2.25.6
org.geoserver/gs-wms 2.26.0 - 2.26.2Maven
org.geoserver.web/gs-web-app 2.26.0 - 2.26.2Maven
Published Nov 25, 2025
KEV Added Dec 11, 2025
Tracked Since Feb 18, 2026