GeoServer < 2.25.6 / 2.26.x < 2.26.2 XML External Entity

critical Web App Scanning Plugin ID 115075

Synopsis

GeoServer < 2.25.6 / 2.26.x < 2.26.2 XML External Entity

Description

GeoServer versions prior to < 2.25.6, 2.26.x < 2.26.2 are affected by an XML External Entity (XXE) vulnerability. An attacker could exploit this vulnerability by sending a specially crafted XML request to the GeoServer instance, which could lead to unauthorized access to sensitive data, server-side request forgery (SSRF), or denial of service (DoS) attacks.

Solution

Update to GeoServer version 2.25.6 or 2.26.2 or later.

See Also

https://github.com/advisories/GHSA-fjf5-xgmq-5525

https://osgeo-org.atlassian.net/browse/GEOS-11682

Plugin Details

Severity: Critical

ID: 115075

Type: remote

Published: 12/11/2025

Updated: 12/11/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-58360

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2025-58360

Vulnerability Information

CPE: cpe:2.3:a:geoserver:geoserver:*:*:*:*:*:*:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/27/2025

Vulnerability Publication Date: 11/24/2025

CISA Known Exploited Vulnerability Due Dates: 1/1/2026

Reference Information

CVE: CVE-2025-58360