PatchSiren cyber security CVE debrief
CVE-2025-58360 OSGeo CVE debrief
CVE-2025-58360 is a GeoServer vulnerability described as an improper restriction of XML External Entity (XXE) reference handling. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-11 and set a remediation due date of 2026-01-01. Because it is a KEV-listed issue, defenders should treat it as urgent and follow vendor mitigation guidance immediately.
- Vendor
- OSGeo
- Product
- GeoServer
- CVSS
- HIGH 8.2
- CISA KEV
- Listed
- Original CVE published
- 2025-12-11
- Original CVE updated
- 2025-12-11
- Advisory published
- 2025-12-11
- Advisory updated
- 2025-12-11
Who should care
OSGeo GeoServer operators, application owners, platform teams, and security teams responsible for exposed or business-critical GeoServer deployments should prioritize this advisory. Cloud service operators using GeoServer-based services should also review applicable CISA guidance.
Technical summary
The supplied record identifies CVE-2025-58360 as an improper restriction of XML External Entity reference vulnerability in OSGeo GeoServer. The source corpus does not provide version ranges, attack preconditions, or a CVSS score. The key defensive signal in the supplied material is that CISA lists the issue as known exploited, which makes mitigation urgency higher than a routine disclosure.
Defensive priority
High. CISA KEV inclusion indicates confirmed exploitation risk and a required remediation timeline. The supplied due date is 2026-01-01, so affected environments should be reviewed and mitigated without delay.
Recommended defensive actions
- Apply vendor-provided mitigations for GeoServer as referenced in the linked vendor advisory and issue tracker.
- If mitigations are unavailable or cannot be applied in time, discontinue use of the affected product or service path per CISA guidance.
- For cloud services, follow applicable CISA BOD 22-01 guidance.
- Inventory GeoServer deployments and confirm whether any exposed or business-critical instances are affected.
- Track remediation status against the CISA KEV due date of 2026-01-01.
Evidence notes
This debrief is based only on the supplied CISA KEV entry and the official resource links listed in the corpus. The corpus identifies the vulnerability as an OSGeo GeoServer XXE issue and confirms KEV status with dateAdded 2025-12-11 and dueDate 2026-01-01. No CVSS score, affected version range, exploit details, or ransomware-campaign attribution beyond 'Unknown' were provided in the source corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-58360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-58360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-58360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-58360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.