criticalCVSS 9.8Vulnerability

CVE-2026-76904

### Summary An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation: * `jsonArrayContains` function Requires PostGIS 12 or greater with a String or JSON field For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. ### Patches * GeoTools 35.1 * GeoTools 33.5 * GeoTools 34.4 ### Mitigation No mitigation is available: * To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights. ### Impact This vulnerability can lead to execution of arbitrary SQL expressions in the database. ### References * https://osgeo-org.atlassian.net/browse/GEOT-7958 * https://osgeo-org.atlassian.net/browse/GEOT-7959 * https://github.com/geotools/geotools/pull/5829 * https://osgeo-org.atlassian.net/browse/GEOT-7589

Properties

ghsa_id
GHSA-mqjf-5f49-2fjh
severity
critical
summary
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
cvss_score
9.8
cve_id
CVE-2026-76904
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-08-21T20:25:41Z
source_url
https://github.com/advisories/GHSA-mqjf-5f49-2fjh
ghsa_updated
2026-08-21T20:26:30Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]maven/org.geotools.jdbc:gt-jdbc-postgis

AFFECTS (1)

[Software]maven/org.geotools.jdbc:gt-jdbc-postgis

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-76904 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal