{"id":9148,"date":"2025-12-12T10:04:06","date_gmt":"2025-12-12T10:04:06","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/cisa-warns-of-osgeo-geoserver-0-day-vulnerability-exploited-in-attacks\/"},"modified":"2025-12-12T10:04:06","modified_gmt":"2025-12-12T10:04:06","slug":"cisa-warns-of-osgeo-geoserver-0-day-vulnerability-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/12\/cisa-warns-of-osgeo-geoserver-0-day-vulnerability-exploited-in-attacks\/","title":{"rendered":"CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks"},"content":{"rendered":"<p>    CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server.<\/p>\n<p>CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating that threat actors are actively leveraging this <a href=\"https:\/\/cybersecuritynews.com\/chinese-hackers-vpn-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day<\/a> flaw in attacks targeting both public and private sectors.<\/p>\n<p>The newly disclosed vulnerability, tracked as CVE-2025-58360, is classified as an Improper Restriction of XML External Entity (<a href=\"https:\/\/cybersecuritynews.com\/apache-tika-xxe-attack-exposed-online\/\" target=\"_blank\" rel=\"noreferrer noopener\">XXE<\/a>) Reference.<\/p>\n<p>This security gap exists within the application\u2019s handling of XML input. Specifically involving the\u00a0\/geoserver\/wms\u00a0endpoint during\u00a0GetMap\u00a0operations.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Field<\/th>\n<th>Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE ID<\/strong><\/td>\n<td>CVE-2025-58360<\/td>\n<\/tr>\n<tr>\n<td><strong>Name<\/strong><\/td>\n<td>OSGeo GeoServer XXE Vulnerability<\/td>\n<\/tr>\n<tr>\n<td><strong>Description<\/strong><\/td>\n<td>XML input in <code>\/geoserver\/wms<\/code> GetMap is not properly restricted, allowing external XML entities.<\/td>\n<\/tr>\n<tr>\n<td><strong>Related CWE<\/strong><\/td>\n<td>CWE-611<\/td>\n<\/tr>\n<tr>\n<td><strong>Action<\/strong><\/td>\n<td>Apply vendor fixes, follow BOD 22-01 for cloud services, or stop using the product.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Security researchers have determined that the software fails to restrict external entities in XML requests properly.<\/p>\n<p>By exploiting this weakness, remote attackers can define malicious external entities in their requests. Successful exploitation could allow unauthorized actors to view files on the server.<\/p>\n<p>Interact with backend or external systems (Server-Side Request Forgery), or cause <a href=\"https:\/\/cybersecuritynews.com\/jenkins-vulnerability-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service<\/a> conditions.<\/p>\n<p>The confirmation of active exploitation prompted CISA to intervene, requiring federal civilian executive branch (FCEB) agencies to immediately secure their systems.<\/p>\n<p>In accordance with Binding Operational Directive (<a href=\"https:\/\/cybersecuritynews.com\/cwp-os-command-injection-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">BOD<\/a>) 22-01, CISA has mandated that all FCEB agencies must identify and mitigate this vulnerability by January 1, 2026.<\/p>\n<p>While the mandate applies only to federal agencies, CISA strongly urges all organizations that use OSGeo <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-geoserver-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">GeoServer<\/a> to prioritize this update.<\/p>\n<p>The short remediation window reflects the severity of the <a href=\"https:\/\/cybersecuritynews.com\/see-cyber-threats-to-your-companys-industry-region-in-2-seconds\/\" target=\"_blank\" rel=\"noreferrer noopener\">threat <\/a>and the active nature of current campaigns. Administrators are advised to apply the relevant vendor mitigations immediately.<\/p>\n<p>If patches are not yet available for specific configurations, organizations should follow <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA\u2019s<\/a> guidance for cloud services. Consider temporarily discontinuing the use of the affected product until it can be secured.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-osgeo-0-day-vulnerability\/\">CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-osgeo-0-day-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating that threat actors are actively leveraging this zero-day flaw in attacks targeting both public [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648,517],"tags":[130],"class_list":["post-9148","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9148"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9148"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9148\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}