OSGeo GeoServer GeoTools Eval Injection Vulnerability

OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.

Published 14 Sep 2026Updated 14 Sep 202625 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.