Release Notes

CoreSpatial 2026-Q2 Release Announcement

CoreSpatial 2026-Q2 Release Announcement

NGS is pleased to announce the 2026.2 release of CoreSpatial Server, Basemaps and Map Manager.

This quarter's releases continue our disciplined cadence of security hardening across the stack, keeping bundled runtimes and dependencies current against newly disclosed vulnerabilities. A CoreSpatial Portal 2026.2 release candidate (2026.2.1) is currently in testing, building on the 2026.1 MapStore2 rollup; we expect to promote it to a generally available release in the coming weeks.

We also look forward to continued development in the following areas:

  • Bulk tile collection projects via Map Manager UI
  • Expanded image handling capabilities in Map Manager – georectification of commercial drone imagery using JPEG EXIF
  • Direct drone imagery upload to CoreSpatial Portal via Cesium Ion
  • Desktop GIS integration via QGIS

CoreSpatial Server and Basemaps Release Notes

2026.2.2 (05/20/2026)

  • Patch log4j-1.2-api to 2.25.4 to remediate GHSA-h383-gmxw-35v2 in bundled GeoServer 2.28.3 dependencies
  • Refresh RHEL 9 runtime packages in the final Docker image to clear fixed vulnerabilities in glib2 and libpng

2026.2.1 (05/07/2026)

  • Update PostgreSQL JDBC jar to 42.7.11
  • Patch bundled GeoServer 2.28.3 dependencies by updating Log4j to 2.25.4, Bouncy Castle to 1.84, and Jakarta Mail to 1.6.8
  • Remove unused Jetty JASPI support to apply the GHSA-r7p8-xq5m-436c workaround while the compatible Jetty 9.4 patch artifact is unavailable
  • Refresh RHEL 9 runtime packages in the final Docker image to clear fixed vulnerabilities in OpenJDK, Python, libarchive, libcap, libnghttp2, and systemd

CoreSpatial Map Manager Release Notes

2026.2.6 (06/23/2026)

  • Bump Jackson to the 2.22.x line to remediate jackson-databind vulnerabilities (GHSA-j3rv-43j4-c7qm, GHSA-rmj7-2vxq-3g9f, GHSA-5jmj-h7xm-6q6v, and GHSA-hgj6-7826-r7m5)
  • Refresh runtime container packages in the final Docker image to clear recent fixed Ubuntu vulnerabilities in openssl, libssl3t64, libarchive13t64, openjdk-17-jre-headless, liblzma5, libgcrypt20, libsystemd0, and libudev1

2026.2.5 (05/20/2026)

  • Pin tomcat-embed-core to 10.1.55 to remediate two Critical and three High severity CVEs in the Tomcat embedded runtime used with Spring Boot 3.5.14

2026.2.4 (05/13/2026)

  • Patch Ubuntu libarchive vulnerabilities CVE-2025-5918, CVE-2026-4111, and CVE-2025-60753 in the Docker image

2026.2.3 (05/11/2026)

  • Bump Spring Boot to 3.5.14 to remediate GHSA-wwpq-f5c3-7hvx and update Spring Web MVC to 6.2.18
  • Refresh runtime container packages in the final Docker image to clear recent fixed Ubuntu vulnerabilities in libarchive

2026.2.2 (05/07/2026)

  • Update PostgreSQL JDBC to 42.7.11 to remediate GHSA-98qh-xjc8-98pq
  • Refresh runtime container packages in the final Docker image to clear recent fixed Ubuntu vulnerabilities in libarchive, curl, libcurl4t64, liblcms2-2, libnghttp2-14, and sed

2026.2.1 (04/20/2026)

  • Pin tomcat-embed-core to 10.1.54 to remediate one Critical and multiple High/Medium severity CVEs in the Tomcat embedded runtime shipped with Spring Boot 3.5.12
  • Refresh runtime container packages in the final Docker image to clear recent fixed vulnerabilities in libarchive, openssl, and libssl3t64

Want to see CoreSpatial for your mission?