High severity7.2GHSA Advisory· Published Jun 18, 2026· Updated Jun 24, 2026
CVE-2025-27511
CVE-2025-27511
Description
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.geoserver.extension:gs-db2Maven | < 2.27.0 | 2.27.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-g628-r368-6vh7ghsaADVISORY
- github.com/geoserver/geoserver/security/advisories/GHSA-g628-r368-6vh7nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-27511ghsaADVISORY
- nvd.nist.gov/vuln/detail/cve-2023-27867nvdNot ApplicableADVISORY
- github.com/geoserver/geoserver/releases/tag/2.27.0nvdProductRelease NotesWEB
- osgeo-org.atlassian.net/browse/GEOT-7725nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.