GeoCat Map 2026.0 Release Notes¶
GeoCat is pleased to present the rebranded GeoCat Map enterprise distribution of GeoServer technology.
Overview¶
GeoCat Map 2026.0 provides support for publishing geospatial data using open standards.
This distribution is made available to GeoCat customers:
- GeoCat Map Standard distribution provides a web archive (or docker image) of GeoServer bundled with recommended extensions.
New for GeoCat Map 2026 a plugins folder alongside each release, providing an easy migration from GeoServer community distribution. This approach allows access to both rapid-response releases, and continues for long-term support.
-
GeoCat Map Enterprise Premium offers a custom distribution with your selection of extensions backed by GeoCat extended support.
-
GeoCat Live provides a hosted GeoServer environment
GeoCat Map 2026.0 is a recommended upgrade for all our customers and is compatible with GeoCat Bridge for both ArcGIS Desktop and QGIS Desktop.
General¶
This is a major upgrade of GeoCat Map marking our successful completion of the GeoServer 3 project. We are very pleased with the many changes made, both the visual user experience upgrades, and the extensive work on security and under-the-hood updates to the Spring Framework.
GeoCat Map 2026.0 release notes:
- Offers our GeoCat Map Premium customers "predefined war" service with a ready to use war including your selection of supported GeoServer extensions.
- GeoCat Map 2026.0 is proudly open source with the latest GeoServer 3.0.1, GeoWebCache 2.0.1, and GeoTools 35.1 technologies.
Detailed change log:
Security considerations:
-
GeoCat respects the GeoServer coordinated vulnerability disclosure policy, contact us directly to discuss known security vulnerabilities mitigation and resolution availability.
-
The following active exploits are addressed by this release:
-
CVE-2026-76904 Unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers (Critical)
- CVE-2026-27972
- CVE-2026-27592
- CVE-2025-53607
- CVE-2025-27504
- CVE-2025-21625
- CVE-2024-35233
- CVE-2023-41877 GeoServer log file path traversal vulnerability
- CVE-2016-1000027
GeoCat is committed to taking care of our customers and will provide more information as the above vulnerabilities are publicly disclosed. If you have any concerns please contact our help desk.
Known issues:
- Known issues for 2026.0
GeoCat Map Standard¶
GeoCat Map standard provides:
- Drop-in
geoserver.warvia our enterprise repository.
This geoserver.war is pre-packaged with several plugins such as control-flow that are highly recommended.
- For GeoCat Map 2026 wach release now includes a
pluginsfolder allowing easy migration for GeoServer community releases to both rapid response, and long term support releases.
GeoServer Enterprise Premium¶
- OIDC Extension
The OIDC extension is a replacement for the previously available OAuth2 and Keycloak extensions.
Please contact support for assistance, a migration guide is available.
- OGCAPI Extensions
The OGCAPI extensions are making rapid progress and have been further integrated into the user interface. Service pages refactored by topic, integrating configuration of OpenGIS W*S services and OGCAPI Services.
The following "Testbed 15" module is not presently available for preview:
gs-ogcapi-images: experiment to dynamically manage image mosaic updates