SQL injection in geotools - #VU142660
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL expressions in the database.
The vulnerability exists due to sql injection in the jsonArrayContains filter function when executing OGC Filters against PostGIS layers. A remote attacker can send a specially crafted filter input to execute arbitrary SQL expressions in the database.
The issue requires PostGIS 12 or greater with a String or JSON field.
Note, the vulnerability is being actively exploited in the wild against GeoServer instances.
Affected software
GeoServer
Remediation
GeoServer - addressed in versions 2.27.6, 2.28.5, 3.0.1