Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Osgeo

First CVE: Mar 31, 2009Active for: 17 yearsTotal CVEs: 57
59.1
VTI Score
TOP TARGET

Osgeo maintains a specialized portfolio of geospatial software tools and libraries—including MapServer, GeoServer, GDAL, GeoNetwork, and OWSLib—that serve critical roles in mapping, spatial data processing, and geographic information systems across government, research, and enterprise environments. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the memory-safety demands of native geospatial processing and the complexity of request parsing in server components. The exposure recurs across these core products through weakness classes including buffer overflows and improper bounds checking in memory operations, server-side request forgery in data-fetching workflows, XML entity expansion vulnerabilities, and exposure of sensitive geographic or configuration data—all signature risks in systems that handle untrusted spatial input and make external requests to remote data sources. Because these geospatial tools often sit at the boundary between user input and critical infrastructure (mapping services, emergency response, resource management), defenders should prioritize patching and restrict network access to exposed instances. Live severity and exploit-availability figures are shown alongside this summary.

FAUCET AI Generated
57
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Osgeo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2009
17 years ago
Most Recent CVE
Jun 18, 2026
36 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-25157CRITICAL
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language a
Feb 21, 20239.884NOYES
CVE-2023-43795CRITICAL
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to p
Oct 25, 20239.872NOYES
CVE-2025-30220CRITICAL
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulne
Jun 10, 20259.166NOYES
CVE-2021-40822HIGH
GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
May 2, 20227.546NOYES
CVE-2024-29198HIGH
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the
Jun 10, 20258.238NOYES
CVE-2011-2975MEDIUM
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or
Aug 1, 20116.833NOYES
CVE-2025-52465HIGH
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated adm
Jun 18, 20267.232NONO
CVE-2019-17545CRITICAL
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
Oct 14, 20199.832NONO
CVE-2022-0699CRITICAL
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified im
Oct 17, 20229.831NONO
CVE-2026-4738CRITICAL
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with pro
Mar 24, 20269.430NONO
View all 57 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products57 CVEs
30%
54%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (17.5%)
Network33 (57.9%)
Unknown14 (24.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (75.4%)
High0 (0.0%)
Unknown14 (24.6%)
User Interaction
None39 (68.4%)
Unknown14 (24.6%)
Required3 (5.3%)
Privileges Required
Low10 (17.5%)
High5 (8.8%)
None28 (49.1%)
Unknown14 (24.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (57 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
10.5% of CVEs· 96th percentile
ExploitDB
1 CVE
1.8% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Osgeo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Osgeo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Osgeo's Products

View all 6 CNAs →

Top CWEs