VYPR

Geotools

by Geotools

Source repositories

CVEs (6)

  • CVE-2024-36401CriKEVJul 1, 2024
    risk 0.80cvss 9.8epss 1.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a…

  • CVE-2024-36404CriJul 2, 2024
    risk 0.63cvss 9.8epss 0.76

    GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions…

  • CVE-2025-30220CriJun 10, 2025
    risk 0.61cvss 9.9epss 0.42

    GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with…

  • CVE-2026-76904CriAug 21, 2026
    risk 0.57cvss 9.8epss 0.02

    GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains`…

  • CVE-2023-25158CriFeb 21, 2023
    risk 0.57cvss 9.8epss 0.01

    GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters…

  • CVE-2022-24818HigApr 13, 2022
    risk 0.00cvss 8.2epss 0.02

    GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform unchecked JNDI lookups, which in turn can be used to perform class deserialization and result in arbitrary code execution. Similar…