Skip to content
COOEY

FAIL › dossier

GeoServer

PRODUCT

· dossier confidence 50%

GeoServer, an open-source GIS software server, has experienced significant security vulnerabilities, including high-severity remote code execution and XML external entity attacks.

PROFILE
CategoryGIS softwareWhat they doGeoServer is an open-source software server that allows users to view and edit geospatial data.
SECURITY POSTURE

GeoServer has faced multiple high-severity vulnerabilities, indicating potential security risks.

Notable failures
  • CVE-2024-36401 (high [RCE])
  • CVE-2025-58360 (high [RCE])
Patterns: Unauthenticated remote code execution through unsafe evaluations.; Exposure to XML external entity attacks.
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2024-07-15 CVE-2024-36401 high OSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions.
2025-12-11 CVE-2025-58360 high GeoServer exposed to XML external entity attacks
Open questions: How are these vulnerabilities being addressed by the development team? · Has there been a change in the security posture of GeoServer since these incidents?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:43:13.247997+00:00