Skip to content
COOEY

FAIL › dossier

OSGeo

VENDOR

· dossier confidence 50%

OSGeo's GeoServer component has repeatedly demonstrated critical vulnerabilities, including multiple remote code execution flaws. This history suggests a need for improved security practices and rigorous code review processes. The organization's open-source nature may contribute to the rapid discovery and exploitation of these weaknesses.

PROFILE
CategoryGeospatialWhat they doOSGeo develops and maintains open-source geospatial software libraries and tools. It provides a platform for collaborative development of geographic software.
SECURITY POSTURE

OSGeo has a history of high-severity remote code execution vulnerabilities in its GeoServer component. These vulnerabilities indicate a pattern of insufficient input validation and improper neutralization of directives.

Notable failures
  • CVE-2025-58360 (RCE) - XML external entity attacks
  • CVE-2024-36401 (RCE) - XPath expression vulnerability
  • CVE-2022-24816 (RCE) - Code injection vulnerability
Patterns: Repeated RCE vulnerabilities; Insufficient input validation; Improper directive neutralization
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2024-07-15 CVE-2024-36401 high OSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions.
2025-12-11 CVE-2025-58360 high GeoServer exposed to XML external entity attacks
2024-06-26 CVE-2022-24816 high OSGeo GeoServer JAI-EXT allows remote code execution via network-provided Jiffle scripts.
Open questions: What is OSGeo's current security development lifecycle? · What is the ownership structure of OSGeo? · What is the size of OSGeo? · What is the website for OSGeo?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:15:49.138846+00:00