FAIL › dossier
OSGeo
VENDOR· dossier confidence 50%
OSGeo's GeoServer component has repeatedly demonstrated critical vulnerabilities, including multiple remote code execution flaws. This history suggests a need for improved security practices and rigorous code review processes. The organization's open-source nature may contribute to the rapid discovery and exploitation of these weaknesses.
PROFILE
CategoryGeospatialWhat they doOSGeo develops and maintains open-source geospatial software libraries and tools. It provides a platform for collaborative development of geographic software.
SECURITY POSTURE
OSGeo has a history of high-severity remote code execution vulnerabilities in its GeoServer component. These vulnerabilities indicate a pattern of insufficient input validation and improper neutralization of directives.
Notable failures
- CVE-2025-58360 (RCE) - XML external entity attacks
- CVE-2024-36401 (RCE) - XPath expression vulnerability
- CVE-2022-24816 (RCE) - Code injection vulnerability
Patterns: Repeated RCE vulnerabilities; Insufficient input validation; Improper directive neutralization
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-07-15 | CVE-2024-36401 | high | OSGeo GeoServer's GeoTools component allows unauthenticated remote code execution via unsafely evaluated XPath expressions. |
| 2025-12-11 | CVE-2025-58360 | high | GeoServer exposed to XML external entity attacks |
| 2024-06-26 | CVE-2022-24816 | high | OSGeo GeoServer JAI-EXT allows remote code execution via network-provided Jiffle scripts. |
Open questions: What is OSGeo's current security development lifecycle? · What is the ownership structure of OSGeo? · What is the size of OSGeo? · What is the website for OSGeo?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-29 04:15:49.138846+00:00