Osgeo maintains a specialized portfolio of geospatial software tools and libraries—including MapServer, GeoServer, GDAL, GeoNetwork, and OWSLib—that serve critical roles in mapping, spatial data processing, and geographic information systems across government, research, and enterprise environments. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, reflecting the memory-safety demands of native geospatial processing and the complexity of request parsing in server components. The exposure recurs across these core products through weakness classes including buffer overflows and improper bounds checking in memory operations, server-side request forgery in data-fetching workflows, XML entity expansion vulnerabilities, and exposure of sensitive geographic or configuration data—all signature risks in systems that handle untrusted spatial input and make external requests to remote data sources. Because these geospatial tools often sit at the boundary between user input and critical infrastructure (mapping services, emergency response, resource management), defenders should prioritize patching and restrict network access to exposed instances. Live severity and exploit-availability figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osgeo over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25157CRITICAL GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language a | Feb 21, 2023 | 9.8 | 84 | NO | YES |
CVE-2023-43795CRITICAL GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to p | Oct 25, 2023 | 9.8 | 72 | NO | YES |
CVE-2025-30220CRITICAL GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulne | Jun 10, 2025 | 9.1 | 66 | NO | YES |
CVE-2021-40822HIGH GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. | May 2, 2022 | 7.5 | 46 | NO | YES |
CVE-2024-29198HIGH GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the | Jun 10, 2025 | 8.2 | 38 | NO | YES |
CVE-2011-2975MEDIUM Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or | Aug 1, 2011 | 6.8 | 33 | NO | YES |
CVE-2025-52465HIGH GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a vulnerability exists that allows an authenticated adm | Jun 18, 2026 | 7.2 | 32 | NO | NO |
CVE-2019-17545CRITICAL GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. | Oct 14, 2019 | 9.8 | 32 | NO | NO |
CVE-2022-0699CRITICAL A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified im | Oct 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-4738CRITICAL Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in OSGeo gdal (frmts/zlib/contrib/infback9 modules). This vulnerability is associated with pro | Mar 24, 2026 | 9.4 | 30 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osgeo.
Media articles that mention a CVE ID that affects a product developed by Osgeo — matched by CVE ID, not by vendor name.