VMTech
Discuss a project

GeoServer releases fixes for actively probed PostGIS SQL injection

GeoServer releases fixes for actively probed PostGIS SQL injection

GeoServer has released versions 3.0.1, 2.28.5 and 2.27.6 to fix a critical SQL injection vulnerability that was probed in active exploitation attempts shortly after public disclosure. The flaw is tracked as GHSA-mqjf-5f49-2fjh, carries a CVSS score of 9.8, and may lead to remote code execution under certain configurations.

The issue was publicly disclosed on 12 August 2026. watchTowr said it began seeing exploitation attempts within hours and recorded hundreds of attempts from a small pool of IP addresses. Its researchers said the observed activity consisted of probes intended to identify vulnerable internet-facing systems, with errors being triggered rather than follow-on actions observed at that point.

How the GeoServer flaw works

GeoServer maintainers said the vulnerability occurs when OGC Filters are executed with the PostGIS DataStore implementation and its jsonArrayContains function. On PostGIS 12 and later, the function can write a supplied value into generated SQL without escaping it.

Exploitation requires PostGIS 12 or newer and a String or JSON field. The affected Maven package is org.geotools:gt-jdbc-postgis. Version 35.0 is fixed in 35.1; versions from 34.0 are fixed in 34.5; and versions from 33.1 are fixed in 33.6.

Project owner Jody Garnett of GeoCat said the weakness was a known issue in the GeoTools library and had been addressed in the three GeoServer releases. The advisory also describes the bug as a regression of CVE-2023-25158, another critical SQL injection issue fixed with CVE-2023-25157 in February 2023.

Why exposure needs prompt review

watchTowr warned that GeoServer has previously been targeted at scale and that several of its vulnerabilities appear in CISA's Known Exploited Vulnerabilities catalog. The 2024 GeoServer GeoTools flaw CVE-2024-36401, also scored 9.8, was actively exploited to incorporate compromised devices into DDoS and cryptocurrency-mining botnets and residential proxy networks.

The new case also sits within a wider pattern of exploitation activity described in Cisco flaws, ClickFix chains and AI agent incidents involving Cisco vulnerabilities, ClickFix chains and incidents affecting AI agents, while its immediate technical trigger is specific to GeoServer's PostGIS integration.

Actions for GeoServer operators

Organizations should identify GeoServer instances, especially publicly accessible deployments using the affected PostGIS DataStore configuration. They should install the applicable fixed GeoServer release, restrict unnecessary public access, and monitor for suspicious OGC Filter requests and errors. These steps provide a practical basis for reducing exposure while verifying that the deployed GeoTools dependency is on a corrected version.

#geoserver#sqlinjection#postgis#cybersecurity
Open analytics
On the site 1 views
min read 3 17.08.2026
Instagram

GeoServer releases fixes for actively probed PostGIS SQL injection

Open the post on Instagram ↗