a hacker tweeted a map-server bug tuesday morning. by wednesday, attackers were already inside

GeoServer's jsonArrayContains function scored a 9.8, needed zero credentials, and WatchTowr watched the exploitation start within hours of the tweet…

Aliteq
Priya Nair · Software & Systems Editor

The short version

Tracked as GHSA-mqjf-5f49-2fjh (geotools library) and GHSA-7g5f-wrx8-5ccf (GeoServer's OGC filter handling), CVSS 9.8 out of 10.

The short version

Unauthenticated SQL injection in the jsonArrayContains() OGC filter function, exploitable against PostGIS-backed layers on PostGIS 12 or newer with a string or JSON field.

The short version

Disclosed publicly by researcher @q1uf3ng at 10:46 UTC on August 12, 2026; WatchTowr recorded exploitation attempts within hours.

The short version

Fixed in GeoServer 3.0.1, 2.28.5, and 2.27.6, and in the underlying gt-jdbc-postgis library versions 35.1, 34.5, and 33.6.

The short version

It's a regression of CVE-2023-25158, a nearly identical SQL injection GeoServer already patched back in February 2023.

The RCE part isn't automatic

SQL injection alone gets an attacker your database. Full remote code execution needs the database account GeoServer connects with to have superuser-level rights on Postgres — which, on a lot of GIS…

Aliteq

Read the full story

a hacker tweeted a map-server bug tuesday morning. by wednesday, attackers were already inside

Read the full story on Aliteq