Sploitus

CVE-2025-27511

No indexed exploits for CVE-2025-27511 yet

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.

Osgeo Geoserver
< 2.27.0
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
1.1% (62th percentile)
Weakness
CWE-74, CWE-502
NVD status
Analyzed
Published
2026-06-18
CVE-2025-27511 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-27511 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-27511 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.