PT-2026-79450 · Postgis+1 · Postgis+1

CVE-2026-76904

·

Published

2026-08-14

·

Updated

2026-08-25

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GeoTools versions 30.5 through 33.5 GeoTools version 34.4
Description An SQL injection flaw exists when executing OGC Filters with the PostGIS DataStore implementation. The issue occurs within the jsonArrayContains() function, which fails to escape the <value> parameter before inserting it into generated SQL queries. This exploitation requires the use of PostGIS version 12 or greater with a String or JSON field.
Recommendations Update GeoTools versions 30.5 through 33.5 to version 33.6. Update GeoTools version 34.4 to version 34.5. Configure the PostGIS connection pool with limited rights to restrict the scope of potential SQL injection.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12700
CVE-2026-76904
GHSA-MQJF-5F49-2FJH

Affected Products

Geotools
Postgis