CVE-2025-27511

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*

History

22 Jun 2026, 17:58

Type Values Removed Values Added
References () https://github.com/geoserver/geoserver/releases/tag/2.27.0 - () https://github.com/geoserver/geoserver/releases/tag/2.27.0 - Product, Release Notes
References () https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7 - () https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7 - Vendor Advisory
References () https://nvd.nist.gov/vuln/detail/cve-2023-27867 - () https://nvd.nist.gov/vuln/detail/cve-2023-27867 - Not Applicable
References () https://osgeo-org.atlassian.net/browse/GEOT-7725 - () https://osgeo-org.atlassian.net/browse/GEOT-7725 - Issue Tracking
First Time Osgeo
Osgeo geoserver
CPE cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*

18 Jun 2026, 18:04

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-18 16:16

Updated : 2026-06-24 05:17


NVD link : CVE-2025-27511

Mitre link : CVE-2025-27511

CVE.ORG link : CVE-2025-27511


JSON object : View

Products Affected

osgeo

  • geoserver
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-502

Deserialization of Untrusted Data