Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

geoserver — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting geoserver. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GeoServer is an open-source Java-based server designed to share and edit geospatial data, primarily serving as a standard-compliant OGC web feature server for GIS applications. Its widespread adoption in mapping infrastructure has made it a frequent target for attackers, resulting in 28 recorded CVEs. Historically, vulnerabilities have predominantly stemmed from insecure deserialization, leading to remote code execution, alongside cross-site scripting and improper access control issues that enable privilege escalation. A notable incident involved a critical RCE flaw in the WMS GetMap functionality, allowing unauthenticated attackers to execute arbitrary commands on the host system. The software’s reliance on complex Java dependencies often introduces supply chain risks, while its default configurations sometimes expose administrative interfaces to the public internet. These factors collectively highlight the necessity for rigorous patch management and strict network segmentation to mitigate exploitation of its known attack surface.

Found 2 results / 31 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-58175 GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution — org.geoserver.web:gs-web-app CWE-20 6.5 Medium 2026-06-18
CVE-2025-52465 GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page — org.geoserver.web:gs-web-app CWE-73 7.2 High 2026-06-18

This page lists every published CVE security advisory associated with geoserver. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.