CVE-2025-58360 is a high-severity XML External Entity (XXE) vulnerability in GeoServer’s Web Map Service (WMS) GetMap operation. According to the NIST/NVD entry, the application accepts XML input through the /geoserver/wms endpoint and an unauthenticated attacker can submit crafted XML to trigger XXE processing. Affected releases include GeoServer 2.26.0 up to (but not including) 2.26.2, and 2.25.x versions prior to 2.25.6. Successful exploitation can lead to disclosure of local files or access to internal network resources (SSRF-style impact), with risk depending on server configuration and deployed data layers. Vendor advisories classify the issue as high severity and provide patched releases and updates. The IONIX research team validated the impact through successful exploit reproduction, confirmed findings are detailed in this post.
References:

