📦 Geotools

by Geotools

🔍 What is Geotools?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-30220

CRITICAL CVSS 9.9 Jun 10, 2025

This XXE vulnerability in GeoServer's GeoTools Schema class allows attackers to read arbitrary files from the server or perform server-side request forgery when processing malicious XML documents. It ...

CVE-2024-36401

CRITICAL CVSS 9.8 Jul 1, 2024

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on GeoServer instances by sending specially crafted OGC requests. It affects ALL default GeoServer installations du...

CVE-2022-24818

HIGH CVSS 8.2 Apr 13, 2022

CVE-2022-24818 is a JNDI injection vulnerability in GeoTools that allows remote code execution when user-controlled JNDI strings are processed. Similar to Log4Shell, it enables attackers to load malic...