CRITICAL 9.8 GitHub

CVE-2026-76904

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

### Summary An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation: * `jsonArrayContains` function Requires PostGIS 12 or greater with a String or JSON field For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. ### Patches * GeoTools 35.1 * GeoTools 33.5 * GeoTools 34.4 ### Mitigation No mitigation is available: * To limit scope of SQL Injec

Affected Products

References

Published: 2026-08-21 · Source: GitHub · Feed updated: 2026-08-21
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-21 via GitHub. Affected: maven/org.geotools.jdbc:gt-jdbc-postgis = 35.0, maven/org.geotools.jdbc:gt-jdbc-postgis >= 34.0, < 34.5, maven/org.geotools.jdbc:gt-jdbc-postgis >= 30.5, < 33.6.

Risk Timeline

CVE Disclosed2026-08-21 · -1 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-61798netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toHIGH8.1
CVE-2026-54148http4k: `DigestAuthProvider.verify` did not bind to request URIHIGH8.1
CVE-2026-63202netty-incubator-codec-ohttp BinaryHttpParser: Unauthenticated CPU-exhaustion DoSHIGH7.5
CVE-2026-63124netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length fiHIGH7.5
CVE-2026-53752docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of SerHIGH7.5
CVE-2026-53659http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GHIGH7.5
vulnfeed aggregates 11627 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.