ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds an OSGeo GeoServer flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-58360CVE-2024-36401

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-36401
Unauthenticated RCE in OSGeo GeoServer via GeoTools XPath Injection

OSGeo GeoServer ships the GeoTools library, which evaluates feature property names directly as XPath expressions without proper neutralization (CWE-95), so attacker-supplied input is executed as code rather than treated as data. A remote, unauthenticated attacker triggers the flaw by sending specially crafted requests to a GeoServer service, causing the injected expression to be evaluated in the server's context. Successful exploitation results in remote code execution on the host running GeoServer, giving the attacker control over the mapping server and any data or credentials it can reach. Any organization running GeoServer is affected, and the underlying GeoTools flaw also extends to dependent applications such as GeoNetwork, which shipped its own fix for an unauthenticated RCE chain affecting government geoportal backends. The flaw is being actively exploited: it was added to CISA KEV on 2024-07-15, and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Upgrade GeoServer to the fixed releases identified in the OSGeo advisory (2.23.6, 2.24.4 or 2.25.2, or later); where upgrading is not immediately possible, restrict access to GeoServer's public endpoints per vendor mitigations or discontinue use of the product per the KEV required action. Organizations running GeoNetwork or other GeoTools-based applications should apply those vendors' fixes as well. Given active exploitation, hunt for signs of compromise such as unexpected child processes spawned by the GeoServer Java process, new files or services on the host, and unusual map/feature service request patterns.

9.8100% KEV PoC ×3
  • OSGeo GeoServer Multiple releases prior to the vendor-patched builds (fixed in the 2.23.x, 2.24.x and 2.25.x maintenance lines; exact fixed releases per the OSGeo advisory: 2.2
  • OSGeo GeoNetwork (bundles the vulnerable GeoTools library)
largeTens of thousands of internet-exposed instances (roughly 20,000-40,000 GeoServer endpoints visible in public internet scans), with substantially more internal…
CVE-2025-58360
Actively Exploited XXE in OSGeo GeoServer WMS GetMap Endpoint

GeoServer, an open source server for sharing and editing geospatial data, is vulnerable to an XML External Entity (XXE) injection flaw (CWE-611) tracked as CVE-2025-58360. The flaw is triggered when an unauthenticated XML request sent to the /geoserver/wms endpoint with operation GetMap is not sufficiently sanitized or restricted, allowing an attacker to define external entities in the request and have the server resolve them, which can lead to disclosure of local files, SSRF to internal services, and potentially further compromise. It carries a CVSS 3.1 score of 9.8 (critical) with high impact on confidentiality, integrity, and availability, and related reporting describes unauthenticated RCE chains affecting government geoportal backends in this software ecosystem. Any organization running GeoServer 2.26.0 up to but not including 2.26.2, or any version before 2.25.6, is affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-12-11, and EPSS assigns a 64.9% probability of exploitation within 30 days (99th percentile).

Do: Upgrade immediately to GeoServer 2.25.6, 2.26.3, or 2.27.0, which contain the fix. If patching is delayed, restrict or firewall access to the /geoserver/wms endpoint (particularly GetMap requests) and limit the server's ability to fetch external resources; federal agencies must follow BOD 22-01 guidance per the KEV listing. Review WMS access logs for suspicious XML entity usage and outbound connections or file-read activity from the GeoServer host as indicators of exploitation.

9.865% KEV
  • OSGeo GeoServer 2.26.0 through versions before 2.26.2, and all versions before 2.25.6; fixed in 2.25.6, 2.26.3, and 2.27.0
large≈10,000–30,000 internet-exposed GeoServer instances, plus an unknown number of internal deployments (estimate)
Full article504 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 12, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds an OSGeo GeoServer flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an OSGeo GeoServer flaw, tracked as CVE-2025-58360 (CVSS Score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog.

GeoServer is an open-source server that allows users to share and edit geospatial data.

GeoServer (v2.26.0–2.26.1 and v2.25.x before 2.25.6) contained an XML External Entity (XXE) flaw in the /geoserver/wms GetMap endpoint. Because XML input wasn’t properly sanitized, attackers could embed external entities in requests, potentially accessing internal files or triggering server-side requests. The vulnerability is fixed in versions 2.25.6, 2.26.3, and 2.27.0.

“GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified.” reads the advisory. “The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define external entities within the XML request.”

No technical details are yet available on how CVE-2025-58360 is being exploited in attacks in the wild. Canada’s Cyber Centre confirmed on November 28, 2025, that an exploit is already active in the wild.

“Open-source reporting indicates that an exploit for CVE-2025-58360 exists in the wild.” reads the alert published by the Canadian Centre for Cyber Security. “The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by January 1st, 2026.

In September 2025, US CISA revealed that threat actors exploited an unpatched vulnerability in GeoServer to breach a U.S. federal civilian agency’s network.

Threat actors breached a U.S. federal agency via unpatched GeoServer flaw, tracked as CVE-2024-36401 (CVSS score of 9.8), which is a critical remote code execution (RCE) issue.

In mid-July 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.

CISA launched incident response at a U.S. FCEB agency after its EDR tool detected potential malicious activity. The attackers gained access to the agency’s network on July 11, 2024.

Once inside the agency’s network, the attackers exploited the same vulnerability to access a second GeoServer and moved laterally to two other servers.

Threat actors moved laterally to a web and SQL server, deploying web shells like China Chopper and scripts for persistence, remote access, and privilege escalation. They also leveraged living-off-the-land techniques to evade detection.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185604/hacking/u-s-cisa-adds-an-osgeo-geoserver-flaw-to-its-known-exploited-vulnerabilities-catalog.html