PT-2026-79450 · Postgis+1 · Postgis+1
CVE-2026-76904
·
Published
2026-08-14
·
Updated
2026-08-25
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GeoTools versions 30.5 through 33.5
GeoTools version 34.4
Description
An SQL injection flaw exists when executing OGC Filters with the PostGIS DataStore implementation. The issue occurs within the
jsonArrayContains() function, which fails to escape the <value> parameter before inserting it into generated SQL queries. This exploitation requires the use of PostGIS version 12 or greater with a String or JSON field.Recommendations
Update GeoTools versions 30.5 through 33.5 to version 33.6.
Update GeoTools version 34.4 to version 34.5.
Configure the PostGIS connection pool with limited rights to restrict the scope of potential SQL injection.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geotools
Postgis