THREAT OPS › Threat News › [GHSA] GHSA-mqjf-5f49-2fjh (critical) — GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
[GHSA] GHSA-mqjf-5f49-2fjh (critical) — GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
GHSA-mqjf-5f49-2fjh Severity: critical CVE: CVE-2026-76904
GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers
### Summary
An SQL Injection Vulnerability has been found when executing OGC Filters with PostGIS DataStore implementation:
* `jsonArrayContains` function Requires PostGIS 12 or greater with a String or JSON field
For PostG
Indicators of compromise
- CVE-2026-76904cve
- https://osgeo-org.atlassian.net/browse/GEOT-7958url
- https://osgeo-org.atlassian.net/browse/GEOT-7959url
- https://osgeo-org.atlassian.net/browse/GEOT-7589url
Original source: https://github.com/advisories/GHSA-mqjf-5f49-2fjh