By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
Computing

CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog

News Room
Last updated: 2025/12/12 at 12:21 AM
News Room Published 12 December 2025
Share
CISA Flags Actively Exploited GeoServer XXE Flaw in Updated KEV Catalog
SHARE

Dec 12, 2025Ravie LakshmananVulnerability / Server Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting OSGeo GeoServer to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild.

The vulnerability in question is CVE-2025-58360 (CVSS score: 8.2), an unauthenticated XML External Entity (XXE) flaw that affects all versions prior to and including 2.25.5, and from versions 2.26.0 through 2.26.1. It has been patched in versions 2.25.6, 2.26.2, 2.27.0, 2.28.0, and 2.28.1. Artificial intelligence (AI)-powered vulnerability discovery platform XBOW has been acknowledged for reporting the issue.

“OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request,” CISA said.

Cybersecurity

The following packages are affected by the flaw –

  • docker.osgeo.org/geoserver
  • org.geoserver.web:gs-web-app (Maven)
  • org.geoserver:gs-wms (Maven)

Successful exploitation of the vulnerability could allow an attacker to access arbitrary files from the server’s file system, conduct Server-Side Request Forgery (SSRF) to interact with internal systems, or launch a denial-of-service (DoS) attack by exhausting resources, the maintainers of the open-source software said in an alert published late last month.

There are currently no details available on how the security defect is being abused in real-world attacks. However, a bulletin from the Canadian Centre for Cyber Security on November 28, 2025, said “an exploit for CVE-2025-58360 exists in the wild.”

It’s worth noting that another critical flaw in the same software (CVE-2024-36401, CVSS score: 9.8) has been exploited by multiple threat actors over the past year. Federal Civilian Executive Branch (FCEB) agencies are advised to apply the required fixes by January 1, 2026, to secure their networks.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Four Game-Changing Upgrades Are Rumored To Come To Apple Studio Display 2 – BGR Four Game-Changing Upgrades Are Rumored To Come To Apple Studio Display 2 – BGR
Next Article After OpenAI deal, Disney demands Google cease-and-desist After OpenAI deal, Disney demands Google cease-and-desist
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Xiaomi’s supercar could meet annual goal overnight with 10k orders · TechNode
Xiaomi’s supercar could meet annual goal overnight with 10k orders · TechNode
Computing
Speed Across the Galaxy Next Year in Star Wars: Galactic Racer
Speed Across the Galaxy Next Year in Star Wars: Galactic Racer
News
ByteDance appoints new leader for AI video tool Jimeng · TechNode
ByteDance appoints new leader for AI video tool Jimeng · TechNode
Computing
Nest Doorbell (Wired, 3rd Gen) Review: Sharp 2K Video Paired With Next-Level AI
Nest Doorbell (Wired, 3rd Gen) Review: Sharp 2K Video Paired With Next-Level AI
News

You Might also Like

Xiaomi’s supercar could meet annual goal overnight with 10k orders · TechNode
Computing

Xiaomi’s supercar could meet annual goal overnight with 10k orders · TechNode

5 Min Read
ByteDance appoints new leader for AI video tool Jimeng · TechNode
Computing

ByteDance appoints new leader for AI video tool Jimeng · TechNode

2 Min Read
Ten million meals, zero safety nets — JD.com aims to change it · TechNode
Computing

Ten million meals, zero safety nets — JD.com aims to change it · TechNode

8 Min Read
Honor announces Alpha Strategy at MWC 2025, pledging  billion for AI ecosystem development · TechNode
Computing

Honor announces Alpha Strategy at MWC 2025, pledging $10 billion for AI ecosystem development · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?