BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA Flags High-Severity Vulnerability in OSGeo GeoServer Software

CISA Adds High-Severity Unauthenticated XXE Vulnerability in OSGeo GeoServer to Known Exploited Vulnerabilities Catalog Amid Active Exploitation and Mandated Federal Patching by January 2026

  • CISA has added a high-severity vulnerability affecting OSGeo GeoServer to its Known Exploited Vulnerabilities catalog due to active exploitation.
  • The flaw, CVE-2025-58360, is an unauthenticated XML External Entity (XXE) vulnerability impacting multiple GeoServer versions.
  • The issue allows attackers to access server files, conduct internal network interactions, or cause denial-of-service attacks.
  • Patched versions of GeoServer have been released, and federal agencies must apply fixes by January 1, 2026.
  • An exploit is confirmed to exist in the wild, with another critical GeoServer flaw previously exploited by threat actors.

On December 11, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) included a significant security vulnerability in OSGeo GeoServer in its Known Exploited Vulnerabilities catalog. This decision followed evidence showing the flaw is actively exploited in real-world attacks.

- Advertisement -

The vulnerability, identified as CVE-2025-58360 with a CVSS score of 8.2, is an unauthenticated XML External Entity (XXE) issue. XXE flaws allow attackers to manipulate XML input to access unauthorized data or services. It affects all versions prior to and including 2.25.5 and 2.26.0 through 2.26.1. The flaw has been resolved in GeoServer versions 2.25.6, 2.26.2, 2.27.0, 2.28.0, and 2.28.1.

According to CISA, the vulnerability arises when the application processes XML requests via the /geoserver/wms GetMap operation. Attackers can define external entities in these XML inputs, which bypasses proper restrictions. This can lead to reading arbitrary files on the server, performing Server-Side Request Forgery (SSRF) to interact with internal systems, or causing denial-of-service (DoS) conditions by consuming resources.

Affected GeoServer packages include docker.osgeo.org/geoserver and Maven packages org.geoserver.web:gs-web-app and org.geoserver:gs-wms. The vulnerability was initially reported by the AI-powered platform XBOW.

A security advisory from the Canadian Centre for Cyber Security on November 28, 2025, stated that an exploit for this vulnerability exists in the wild. While specific attack methods are not detailed, the advisory underscores the urgency of patching affected systems.

- Advertisement -

Adding to concerns, another critical GeoServer vulnerability (CVE-2024-36401) with a CVSS score of 9.8 has been actively exploited by various threat actors over the past year. Federal Civilian Executive Branch agencies are directed to implement required patches by January 1, 2026, to protect their networks.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SHIB: How a $13 Investment Could Have Made Millions

Shiba Inu (SHIB) price remains down approximately 94% from its 2021 all-time high of...

U.S. seizes $1B in Iranian crypto assets in economic crackdown

The U.S. Treasury has seized roughly $1 billion in Iranian cryptocurrency assets, doubling a...

Bipartisan Crypto Tax Bill Introduced in House

A bipartisan bill, the PARITY Act, was introduced to modernize digital asset tax rules...

Space Force Awards SpaceX $4.16B for Target-Tracking Satellites

SpaceX secured a $4.16 billion Space Force contract for a satellite-based target tracking network.This...

U.S. Approves First Bitcoin Perpetual Futures

The U.S. Commodity Futures Trading Commission (CFTC) approved the nation's first regulated Bitcoin perpetual...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading