GHSA-mqjf-5f49-2fjhCriticalCVSS 9.8

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

Published
August 21, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:

  • jsonArrayContains function
    Requires PostGIS 12 or greater with a String or JSON field

For PostGIS 12 and greater jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into generated SQL without escaping.

Patches

  • GeoTools 35.1
  • GeoTools 33.5
  • GeoTools 34.4

Mitigation

No mitigation is available:

  • To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.

Impact

This vulnerability can lead to execution of arbitrary SQL expressions in the database.

References

  • https://osgeo-org.atlassian.net/browse/GEOT-7958
  • https://osgeo-org.atlassian.net/browse/GEOT-7959
  • https://github.com/geotools/geotools/pull/5829
  • https://osgeo-org.atlassian.net/browse/GEOT-7589

🎯 Affected products3

  • maven/org.geotools.jdbc:gt-jdbc-postgis:= 35.0
  • maven/org.geotools.jdbc:gt-jdbc-postgis:>= 34.0, < 34.5
  • maven/org.geotools.jdbc:gt-jdbc-postgis:>= 30.5, < 33.6

🔗 References (10)