<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — OSGeo</title><description>Actively exploited vulnerabilities affecting OSGeo products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/osgeo.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-58360 — OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-58360</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-58360</guid><description>GeoServer&apos;s WMS GetMap endpoint fails to properly restrict XML External Entity (XXE) references, meaning an attacker can craft a malicious XML request that causes the server to process external entities it shouldn&apos;t. This can expose sensitive files on the server, enable server-side request forgery, or potentially lead to data exfiltration — all without requiring authentication depending on how the endpoint is exposed. GeoServer is widely used in geospatial infrastructure, making this a high-value target.</description><pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate><category>OSGeo</category><category>GeoServer</category></item></channel></rss>