References https://nvd.nist.gov/vuln/detail/CVE-2025-58360 https://github.com/geoserver/geoserver/security/advisories/GHSA-fjf5-xgmq-5525 https://zhuanlan.zhihu.com/p/1977408813893195757 https://cloud.tencent.com/developer/article/2601739 https://cloud.tencent.com/developer/article/2617074 https://mrxn.net/jswz/geoserver-GetMap-xxe.html https://cn-sec.com/archives/4730923.html https://cn-sec.com/archives/4721490.html https://www.sentinelone.com/vulnerability-database/cve-2025-58360/ https://www.tenable.com/cve/CVE-2025-58360
Related VulnerabilitiesPoCCVE-2026-76904: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionGeoServer jsonArrayContains SQL注入漏洞GeoServer /geoserver/wms 服务器端请求伪造漏洞(CVE-2023-43795)GeoServer /geoserver/topp/wfs 代码执行漏洞PoCCVE-2025-58360: GeoServer - XML External Entity InjectionGeoServer /geoserver/wms GetMap XML 外部实体注入漏洞(CVE-2025-58360)GeoServer GetMap XML外部实体注入漏洞GeoServer 未授权 XML外部实体注入(XXE)漏洞安科瑞-智能环保云平台 /MainMonitor/ReflashMap/GetMapId SQL 注入漏洞