GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataSto…

cve CVE-2025-27511 1 source, 1 claim · Watch

NVD writes:
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue. the claim
Severity
HIGH NVD
CVSS
7.2 NVD
Vendor
geoserver NVD
Product
org.geoserver.extension:gs-db2 NVD
CWE
CWE-74, CWE-502 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-06-18first spoke of it: GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.NVD

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.

What it is to other things

affectsosgeo/geoserver
NVD
made_byosgeo
NVD

In words only, so not counted until a person confirms one:

made_bygeoserver
NVD says “geoserver”
affectsgeoserver/org_geoserver_extension_gs_db2
NVD says “geoserver · org.geoserver.extension:gs-db2”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD7.2
receipt
Source
NVD
Its words
7.2
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-74, CWE-502
receipt
Source
NVD
Its words
CWE-74, CWE-502
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-74, CWE-502
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDorg.geoserver.extension:gs-db2
receipt
Source
NVD
Its words
org.geoserver.extension:gs-db2
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
high
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDtotal
The attacker gains full control of the component, or all of its information.
receipt
Source
NVD
Its words
total
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCtotal
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDgeoserver
receipt
Source
NVD
Its words
geoserver
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "org.geoserver.extension:gs-db2",
            "vendor": "geoserver",
            "versions": [
              {
                "status": "affected",
                "version": "< 2.27.0"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:osgeo:geoserver:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F505198A-5FA2-430C-BD60-610BF1B1B3C3",
                "versionEndExcluding": "2.27.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue."
      },
      {
        "lang": "es",
        "value": "GeoServer es un servidor de código abierto que permite a los usuarios compartir y editar datos geoespaciales. Antes de la versión 2.27.0 de la Extensión GeoServer DB2 DataStore, un administrador puede realizar un ataque JNDI a través de una URL jdbc de DB2 especialmente diseñada, lo que lleva a la Ejecución Remota de Código (RCE). La versión 2.27.0 corrige el problema."
      }
    ],
    "id": "CVE-2025-27511",
    "lastModified": "2026-09-30T21:10:00.190",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-27511",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-23T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-18T16:16:50.960",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Product",
          "Release Notes"
        ],
        "url": "https://github.com/geoserver/geoserver/releases/tag/2.27.0"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://nvd.nist.gov/vuln/detail/cve-2023-27867"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Issue Tracking"
        ],
        "url": "https://osgeo-org.atlassian.net/browse/GEOT-7725"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-74"
          },
          {
            "lang": "en",
            "value": "CWE-502"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
zetlyn/cve-nvd · 2026-06-18
automatable no cvss 7.2 cvss_vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H cwe CWE-74, CWE-502 exploitation none product org.geoserver.extension:gs-db2 severity HIGH status Analyzed technical_impact total vendor geoserver source