GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataSto…
cve CVE-2025-27511 1 source, 1 claim · Watch
NVD writes:
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. the claim
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. the claim
- Severity
- HIGH NVD
- CVSS
- 7.2 NVD
- Vendor
- geoserver NVD
- Product
- org.geoserver.extension:gs-db2 NVD
- CWE
- CWE-74, CWE-502 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-06-18 | first spoke of it: GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. | NVD |
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
What it is to other things
| affects | osgeo/geoserver NVD |
| made_by | osgeo NVD |
In words only, so not counted until a person confirms one:
| made_by | geoserverNVD says “geoserver” |
| affects | geoserver/org_geoserver_extension_gs_db2NVD says “geoserver · org.geoserver.extension:gs-db2” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 7.2receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | NVD | CWE-74, CWE-502receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | org.geoserver.extension:gs-db2receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | HIGH From 7.0 to 8.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | total The attacker gains full control of the component, or all of its information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | geoserverreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "org.geoserver.extension:gs-db2",
"vendor": "geoserver",
"versions": [
{
"status": "affected",
"version": "< 2.27.0"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
"versionEndExcluding": "2.27.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
},
{
"lang": "es",
"value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
}
],
"id": "CVE-2025-27511",
"lastModified": "2026-09-30T21:10:00.190",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.2,
"impactScore": 5.9,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-27511",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-23T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-18T16:16:50.960",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Product",
"Release Notes"
],
"url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
},
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
},
{
"source": "security-advisories@github.com",
"tags": [
"Not Applicable"
],
"url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
},
{
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking"
],
"url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-502"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. zetlyn/cve-nvd · 2026-06-18 | automatable no cvss 7.2 cvss_vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cwe CWE-74, CWE-502 exploitation none product org.geoserver.extension:gs-db2 severity HIGH status Analyzed technical_impact total vendor geoserver | source |