CVE-2024-45747High· 7.2▾ TwilightGeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A server-side template injection (SSTI) vulnerability exist that allows an authenticated administrator to upload FreeMarker templates containing malicious content that can execute OS commands and read from or write to arbitrary files on the server. These FreeMarker templates are used in a plain GeoServer instance (no extension or community modules) for WMS GetFeatureInfo HTML and JSON and WMS GetMap KML and GeoRSS output formats.
The org.geoserver.template.TemplateUtils.getSafeConfiguration() method attempts to block access to the class freemarker.template.utility.Execute but it is still possible to gain access to it and other sensitive functionality by chaining a specific sequence of method calls.
This vulnerability can lead to executing arbitrary code and reading and writing arbitrary files.
GeoServer 2.27.0 addresses this vulnerability with several new application properties:
GEOSERVER_FREEMARKER_BLOCK_LISTGEOSERVER_FREEMARKER_ALLOW_LISTGEOSERVER_FREEMARKER_API_EXPOSEDThese application properties default to restricting the objects template authors can access, and limit access to "getter" methods used to access object properties.
org.geoserver:gs-main < 2.27.0org.geoserver:gs-wms < 2.27.0org.geoserver.web:gs-web-app < 2.27.0Upgrade to a patched release:
org.geoserver:gs-main 2.27.0org.geoserver:gs-wms 2.27.0org.geoserver.web:gs-web-app 2.27.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-27511High· 7.2GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
CVE-2025-52465High· 7.2GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
CVE-2025-58175Medium· 6.5GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution
CVE-2026-89139High· 8.7Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…
CVE-2026-92612Low· 1.0In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8
CVE-2026-68928High· 8.6Acode is a powerful text and code editor for Android