logo

Warning: 0-Day SQL injection in GeoServer, Patch Immediately!

ID: 3bbd5d95-af19-54b4-a698-f76680942377

STIX ID: report--3bbd5d95-af19-54b4-a698-f76680942377

Feed Name: Centre for Cybersecurity Belgium Advisories Feed

Threat Score
80/100

Date Published: 2026-08-17

Date Updated: 2026-08-18

...
...

**GeoTools/PostGIS SQL injection (GHSA-mqjf-5f49-2fjh)**: An unauthenticated SQL injection in the GeoTools gt-jdbc-postgis jsonArrayContains function (affecting versions >=33.1, >=34.0, and 35.0) can lead to arbitrary SQL execution against PostGIS 12+ string/JSON fields and may enable remote code execution in some database configurations; fixes are available in versions 35.1, 34.5, and 33.6 and immediate patching and enhanced monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.