Vendor

OSGeo

As of , 3 OSGeo vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2025-58360.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-58360Improper Restriction of XML External Entity ReferenceOSGeo GeoServerPatch this weekMetasploit module; EPSS 0.610.61
2CVE-2024-36401GeoTools Eval InjectionOSGeo GeoServerPatch this weekMetasploit module; EPSS 0.990.99
3CVE-2022-24816GeoServer JAI-EXT Code InjectionOSGeo JAI-EXTPatch this weekEPSS 0.990.99

Products

  • GeoServer2 entries
  • JAI-EXT1 entry

Added each year

0.511.522024: 2220242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20242
20251
2026none

Used in ransomware