GeoServer Open Source Server Vulnerability Exposing REST API Security Routes
CVE-2025-27505
What is CVE-2025-27505?
GeoServer, an open-source platform for sharing and editing geospatial data, contains a vulnerability that enables a bypass of its default REST API security. This issue arises when accessing the index page through specific paths, including those with extensions such as '.html', resulting in potential exposure of installed extensions. This security gap can be mitigated by updating to the latest versions, 2.26.3 or 2.25.6, or by applying configuration changes in the security settings. For proper remediation, adjust the REST and GWC filter paths as detailed and restart the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
geoserver >= 2.26.0, < 2.26.3 < 2.26.0, 2.26.3
geoserver < 2.25.6 < 2.25.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
