Summary
| Vulnerability Name | XML External Entity (XXE) Injection in GeoServer (CVE-2025-58360) |
| Released on | November 26, 2025 |
| Affected Component | GeoServer |
| Affected Version |
GeoServer < 2.25.6
2.26.0 ≤ GeoServer < 2.26.2
|
| Vulnerability Type | XXE |
| Exploitation Condition |
1. User authentication: not required.
2. Precondition: default configurations.
3. Trigger mode: remote.
|
| Impact | Exploitation difficulty: easy. Attackers can exploit this vulnerability to read arbitrary files without authorization. Severity: high-risk. Attackers can exploit this vulnerability to read sensitive files on the server. |
| Official Solution | Available |
About the Vulnerability
Component Introduction
GeoServer is an open source server written in Java that allows users to share, process, and edit geospatial data. Designed for interoperability, it publishes data from any major spatial data source by using open standards
Vulnerability Description
On November 26, 2025, Sangfor FarSight Labs received notification of the XXE vulnerability in GeoServer (CVE-2025-58360), classified as high-risk in threat level.
Specifically, GeoServer contains an XXE vulnerability that attackers can exploit by crafting malicious XML requests through the GetMap operation of the Web Map Service (WMS). This vulnerability enables attackers to read arbitrary files on the server, manipulate server requests, or launch other attacks.
Affected Versions
The following GeoServer versions are affected:
GeoServer < 2.25.6
2.26.0 ≤ GeoServer < 2.26.2
Solutions
Remediation Solutions
Official Solution
The latest version has been officially released to fix the vulnerability. Affected users are advised to update GeoServer to the latest version.
Temporary Solutions
- Disable unused functional modules to reduce attack entry points.
- Follow the principle of least privilege to strictly control the scope of permissions for sensitive operations.
- Do not expose services to the Internet unless necessary, to limit the access sources to trusted ranges.
- Regularly update the system and components to secure versions, to ensure that known vulnerabilities can be patched at the earliest opportunity.
Sangfor Solutions
Risky Asset Discovery
The following Sangfor service can conduct proactive detection on GeoServer to discover affected assets in batches in business scenarios:
- Athena Endpoint Protection Platform (EPP): The corresponding asset discovery solution has been released. The fingerprint ID is 0003992.
Proactive Vulnerability Detection
The following Sangfor services can proactively detect CVE-2025-58360 vulnerabilities and quickly identify vulnerability risks in batches in business scenarios:
- Athena Extended Detection and Response (XDR): The corresponding detection solution will be released on November 30, 2025. The rule ID is SF-2025-01573.
Vulnerability Monitoring
The following Sangfor services support CVE-2025-58360 vulnerability monitoring, and can quickly identify affected assets and the impact scope in business scenarios in real time through traffic collection:
- Athena Network Detection and Response (NDR): The corresponding monitoring solution will be released on December 04, 2025. The rule ID is 11220020.
- Athena Managed Detection and Response (MDR): The corresponding monitoring solution will be released on December 04, 2025. The rule ID is 11220020. In this case, make sure that Athena MDR is integrated with Athena NDR.
- Athena XDR: The corresponding monitoring solution will be released on December 04, 2025. The rule ID is 11220020.
- Sangfor Traffic Monitoring GPT: Sangfor Traffic Monitoring GPT can detect attacks and threats targeting this vulnerability based on its understanding of attacks and code, without the need to configure rules.
Vulnerability Prevention
The following Sangfor services can effectively block CVE-2025-58360 exploits:
- Athena Next-Generation Firewall (NGFW): The corresponding prevention solution will be released on December 04, 2025. The rule ID is 11220020.
- Sangfor Web Application Firewall (WAF): The corresponding prevention solution will be released on December 04, 2025. The rule ID is 11220020.
- Athena MDR: The corresponding prevention solution will be released on December 04, 2025. The rule ID is 11220020. In this case, make sure that Athena MDR is integrated with Athena NGFW.
- Athena XDR: The corresponding prevention solution will be released on December 04, 2025. The rule ID is 11220020. In this case, make sure that Athena XDR is integrated with Athena NGFW.
Timeline
On November 26, 2025, Sangfor FarSight Labs received notification of the XXE vulnerability in GeoServer (CVE-2025-58360).
On November 26, 2025, Sangfor FarSight Labs released a vulnerability alert.
Reference
https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525
Learn More
Sangfor FarSight Labs researches the latest cyber threats and unknown zero-day vulnerabilities, alerting customers to potential dangers to their organizations, and providing real-time solutions with actionable intelligence. Sangfor FarSight Labs works with other security vendors and the security community at large to identify and verify global cyber threats, providing fast and easy protection for cus