FAIL › dossier
GeoServer
PRODUCT· dossier confidence 50%
GeoServer, an open-source GIS software server, has experienced significant security vulnerabilities, including high-severity remote code execution and XML external entity attacks.
PROFILE
CategoryGIS softwareWhat they doGeoServer is an open-source software server that allows users to view and edit geospatial data.
SECURITY POSTURE
GeoServer has faced multiple high-severity vulnerabilities, indicating potential security risks.
Notable failures
- CVE-2024-36401 (high [RCE])
- CVE-2025-58360 (high [RCE])
Patterns: Unauthenticated remote code execution through unsafe evaluations.; Exposure to XML external entity attacks.
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-07-15 | CVE-2024-36401 | high | OSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions. |
| 2025-12-11 | CVE-2025-58360 | high | GeoServer exposed to XML external entity attacks |
Open questions: How are these vulnerabilities being addressed by the development team? · Has there been a change in the security posture of GeoServer since these incidents?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-07 03:43:13.247997+00:00