CVE-2025-27511 PUBLISHED

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

Assigner: GitHub_M
Reserved: 26.02.2025 Published: 18.06.2026 Updated: 18.06.2026

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor geoserver
Product org.geoserver.extension:gs-db2
Versions
  • Version < 2.27.0 is affected

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE
  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE