GHSA-mqjf-5f49-2fjh

Suggest an improvement
Source
https://github.com/advisories/GHSA-mqjf-5f49-2fjh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mqjf-5f49-2fjh/GHSA-mqjf-5f49-2fjh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mqjf-5f49-2fjh
Aliases
Published
2026-08-21T20:25:41Z
Modified
2026-08-21T20:40:58Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
Details

Summary

An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:

  • jsonArrayContains function
    Requires PostGIS 12 or greater with a String or JSON field

For PostGIS 12 and greater jsonArrayContains(<column>, <pointer>, <value>) function writes <value> into generated SQL without escaping.

Patches

  • GeoTools 35.1
  • GeoTools 33.5
  • GeoTools 34.4

Mitigation

No mitigation is available:

  • To limit scope of SQL Injection the PostGIS connection pool should be configured with limited rights.

Impact

This vulnerability can lead to execution of arbitrary SQL expressions in the database.

References

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-21T20:25:41Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

Maven / org.geotools.jdbc:gt-jdbc-postgis

Package

Name
org.geotools.jdbc:gt-jdbc-postgis
View open source insights on deps.dev
Purl
pkg:maven/org.geotools.jdbc/gt-jdbc-postgis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
35.0
Fixed
35.1

Affected versions

35.*
35.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mqjf-5f49-2fjh/GHSA-mqjf-5f49-2fjh.json"

Maven / org.geotools.jdbc:gt-jdbc-postgis

Package

Name
org.geotools.jdbc:gt-jdbc-postgis
View open source insights on deps.dev
Purl
pkg:maven/org.geotools.jdbc/gt-jdbc-postgis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
34.0
Fixed
34.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mqjf-5f49-2fjh/GHSA-mqjf-5f49-2fjh.json"

Maven / org.geotools.jdbc:gt-jdbc-postgis

Package

Name
org.geotools.jdbc:gt-jdbc-postgis
View open source insights on deps.dev
Purl
pkg:maven/org.geotools.jdbc/gt-jdbc-postgis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
30.5
Fixed
33.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-mqjf-5f49-2fjh/GHSA-mqjf-5f49-2fjh.json"