⤷ Title: High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:22:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Critical Vulnerability #File Exfiltration #GeoServer #ssrf #unauthenticated #WMS GetMap #XML External Entity #xxe
Daily CyberSecurity
High-Severity GeoServer Flaw (CVE-2025-58360) Allows Unauthenticated XXE for File Theft and SSRF
GeoServer patched a High-severity XXE flaw (CVE-2025-58360, CVSS 8.2) in its WMS GetMap operation. The flaw allows unauthenticated remote attackers to read arbitrary files and perform SSRF. Update to v2.27.0.