CRITICALCVSS 9.8Vulnerability

CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. Patches are available in versions 33.6, 34.5, and 33.6. No known workaround is available. To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.

Properties

summary
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
severity
CRITICAL
cvss_severity
CRITICAL
epss_score
0.02403
cvss_score
9.8
retrieved_at
2026-10-05T10:42:26+00:00
ghsa_published
2026-08-21T20:25:41Z
source_url
https://github.com/advisories/GHSA-mqjf-5f49-2fjh
ghsa_updated
2026-08-21T20:26:30Z
ghsa_id
GHSA-mqjf-5f49-2fjh
last_source
FIRST EPSS
score
9.8
cve_id
CVE-2026-76904
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-11T17:54:59+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-21T21:17:06.143
last_modified
2026-09-09T21:06:39.057
epss_percentile
0.83468

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]maven/org.geotools.jdbc:gt-jdbc-postgis

AFFECTS (1)

→[Software]maven/org.geotools.jdbc:gt-jdbc-postgis

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph