CRITICAL 9.8 GitHub
CVE-2026-76904
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
### Summary
An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:
* `jsonArrayContains` function
Requires PostGIS 12 or greater with a String or JSON field
For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping.
### Patches
* GeoTools 35.1
* GeoTools 33.5
* GeoTools 34.4
### Mitigation
No mitigation is available:
* To limit scope of SQL Injec
Affected Products
- maven/org.geotools.jdbc:gt-jdbc-postgis = 35.0
- maven/org.geotools.jdbc:gt-jdbc-postgis >= 34.0, < 34.5
- maven/org.geotools.jdbc:gt-jdbc-postgis >= 30.5, < 33.6
References
- https://github.com/advisories/GHSA-mqjf-5f49-2fjh
- https://github.com/geotools/geotools/security/advisories/GHSA-mqjf-5f49-2fjh
- https://github.com/geotools/geotools/pull/5829
- https://github.com/geotools/geotools/commit/d821c4d321dd91c22e31fcd5b1ce676645da5176
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-21 via GitHub. Affected: maven/org.geotools.jdbc:gt-jdbc-postgis = 35.0, maven/org.geotools.jdbc:gt-jdbc-postgis >= 34.0, < 34.5, maven/org.geotools.jdbc:gt-jdbc-postgis >= 30.5, < 33.6.
Risk Timeline
CVE Disclosed2026-08-21 · -1 days ago
Remediation Resources
Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-61798 | netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through to | HIGH | 8.1 |
| CVE-2026-54148 | http4k: `DigestAuthProvider.verify` did not bind to request URI | HIGH | 8.1 |
| CVE-2026-63202 | netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoS | HIGH | 7.5 |
| CVE-2026-63124 | netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length fi | HIGH | 7.5 |
| CVE-2026-53752 | docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Ser | HIGH | 7.5 |
| CVE-2026-53659 | http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.G | HIGH | 7.5 |
vulnfeed aggregates 11627 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.