Threat reportVulnerabilityTL-2026-2035

Unpatched GeoServer Zero-Day SQL Injection in jsonArrayContains (GHSA-mqjf-5f49-2fjh) Enables Unauthenticated RCE via PostGIS

criticalACTIVE

Unpatched GeoServer Zero-Day SQL Injection in (TL-2026-2035), also tracked as GHSA-mqjf-5f49-2fjh, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-08-16. It has no confirmed attribution, affects OSGeo / GeoServer Project GeoServer, maps to 9 MITRE ATT&CK techniques (T1059.004, T1190, T1213), and is covered by 9 detection rules and 12 indicators of compromise.

CVSS
9.8/10Critical
CVEs
0None referenced
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-2035

Threat ID
TL-2026-2035
Also known as
GHSA-mqjf-5f49-2fjh, GeoServer jsonArrayContains SQL Injection
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, education, agriculture, transport, utilities, engineering, scienceandresearch
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Unpatched GeoServer Zero-Day SQL Injection in

Malware and tooling: GeoServer-jsonArrayContains-PG-RCE

How Unpatched GeoServer Zero-Day SQL Injection in works

A zero-day SQL injection in GeoServer's jsonArrayContains OGC filter function (GHSA-mqjf-5f49-2fjh, CVSS 9.8) lets unauthenticated attackers inject arbitrary SQL against PostGIS-backed layers, escalating to remote code execution via PostgreSQL's COPY TO PROGRAM when the database role has elevated privileges. Disclosed without coordination on 2026-08-12 by researcher q1uf3ng, it was under active internet-wide probing within hours (per WatchTowr) before GeoServer 3.0.1/2.28.5/2.27.6 patched it on 2026-08-14.

GeoServer's jsonArrayContains(<column>, <pointer>, <value>) filter expression, implemented in GeoTools' PostGIS JDBC datastore module (org.geotools:gt-jdbc-postgis), writes the caller-supplied <value> argument directly into generated SQL without escaping. Against a PostGIS 12+ backed layer with a String or JSON field, this lets an unauthenticated remote attacker break out of the intended query string and inject arbitrary SQL through the OGC Filter/CQL_FILTER interface used by WFS GetFeature and related OWS requests. GeoTools' security advisory (GHSA-mqjf-5f49-2fjh, CVSS 9.8, CWE-89) confirms the flaw is a direct regression of CVE-2023-25158 — a 2023 OGC Filter SQL injection in JDBCDataStore implementations — and explicitly notes that CVE-2023-25158's mitigation (enabling prepared statements / disabling encode functions) does not stop this new variant; the advisory further states that setting the JDBC preferQueryMode to extended does not eliminate the raw string-concatenation sink either. The GHSA formally scopes exploitation impact to unauthenticated read, modification, AND deletion of database content (Confidentiality/Integrity/Availability all rated High), not merely disclosure.

Publicly released proof-of-concept code (GitHub repo GeoServer-jsonArrayContains-PG-RCE and an accompanying gist) demonstrates the full exploit chain: a single quote in the injected value breaks the jsonb_path_exists(...) string context, stacked queries are then used to run PostgreSQL's COPY (SELECT 1) TO PROGRAM '<command>', which executes an arbitrary OS command as the database service account. The PoC author notes the attack must be delivered via WFS 2.0 finite-limit/count-style requests specifically — payloads are not interchangeable with WMS GetMap requests, since the two request types traverse different query-building paths with different bracket/alias/trailing-clause structure — and that the PoC intentionally uses local file writes as proof-of-execution markers rather than reverse shells, requiring an explicit --execute flag to prevent accidental live deployment. This RCE path requires the connecting database role to hold the pg_execute_server_program attribute or superuser status — a configuration WatchTowr and others flag as common in default/lower-friction GeoServer-to-PostGIS deployments; the PoC repository explicitly cautions this is not an 'any GeoServer instance can be directly RCE'd' finding. The same stacked-query primitive supports blind boolean/time-based extraction (pg_sleep-based payloads) for reading arbitrary database content even without RCE-level privileges.

The vulnerability was disclosed on X by researcher @q1uf3ng on 2026-08-12 at 10:46 UTC without prior coordination with the GeoServer project, leaving it unpatched with no CVE identifier at disclosure time. WatchTowr (analyst Jake Knott) reported observing hundreds of exploitation/probing attempts against internet-facing GeoServer instances within hours, originating from a small number of source IP addresses; as of the initial wave of reporting (2026-08-13), activity was characterized as reconnaissance — probes triggering database errors to build target lists — with no confirmed follow-on payload delivery or compromise. The GeoServer Project Steering Committee shipped fixed releases (3.0.1, 2.28.5 LTS, 2.27.6) on 2026-08-14, crediting Andrea Aime (GeoSolutions) and Jody Garnett (GeoCat) for the expedited remediation work; the GeoTools GHSA itself (patching gt-jdbc-postgis to 35.1/34.5/33.6), formally published 2026-08-15, separately credits reporters qquang, mrlihd, PhilipPhil, and Quikko — distinct individuals from both the public discloser (@q1uf3ng) and the two developers who implemented the fix, indicating the flaw reached the GeoTools security team through a coordinated report in parallel with (or shortly after) q1uf3ng's public disclosure.

Early secondary reporting was inconsistent on which database backends are affected: SecurityWeek's original report referenced 'PostGIS and Oracle JDBC data stores,' Field Effect's coverage separately referenced H2 database configurations as an RCE-capable backend, and other outlets separately referenced Microsoft SQL Server deployments. The authoritative technical sources — the GHSA advisory and the public PoC — confirm and scope the flaw specifically to the PostGIS JDBC datastore module (org.geotools:gt-jdbc-postgis); this research treats the PostGIS/PostgreSQL exploitation path as evidenced and the Oracle JDBC/H2/MSSQL claims as unconfirmed secondary reporting worth tracking but not yet corroborated by a technical advisory or PoC.

GeoServer has a documented history of being mass-exploited once vulnerability details become public: CVE-2024-36401 (unsafe XPath evaluation via commons-jxpath, CVSS 9.8) was added to the CISA KEV catalog in July 2024 after being used at scale for web shell deployment, DDoS botnets, and cryptocurrency mining, including a documented compromise of a U.S. federal agency within two weeks of disclosure with subsequent botnet and reported espionage-linked activity. Given that history and the platform's exposure across government, education, engineering, and geospatial-data-dependent sectors, defenders should treat the reconnaissance activity already observed as a leading indicator of imminent mass exploitation rather than a contained event.

MITRE ATT&CK techniques used in TL-2026-2035

Execution

T1059.004 Unix Shell

Initial Access

T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

Impact

T1485 Data Destruction; T1565.001 Stored Data Manipulation

Resource Development

T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Unpatched GeoServer Zero-Day SQL Injection in

  • OSGeo / GeoServer Project — GeoServer
    Vulnerable versions: < 3.0.1; 2.28.0 - 2.28.4; 2.27.0 - 2.27.5
    Fixed in: 3.0.1; 2.28.5; 2.27.6
  • GeoTools — org.geotools:gt-jdbc-postgis
    Vulnerable versions: 35.0; 34.0 - 34.4; 33.1 - 33.5
    Fixed in: 35.1; 34.5; 33.6

Remediation for Unpatched GeoServer Zero-Day SQL Injection in

Patches

  • Upgrade to GeoServer 3.0.1, 2.28.5, or 2.27.6 (released 2026-08-14).
  • Upgrade the org.geotools:gt-jdbc-postgis dependency to 35.1, 34.5, or 33.6 per GHSA-mqjf-5f49-2fjh.

Immediate actions

  • Identify and inventory all internet-facing GeoServer instances, especially any backed by PostGIS 12+ with String or JSON-typed fields.
  • Restrict public network access to GeoServer OWS/admin endpoints via firewall rules, VPN, or IP allowlisting until patched.
  • Monitor GeoServer access logs and PostgreSQL logs for jsonArrayContains-related CQL_FILTER requests, malformed JSON filter values, and stacked-query/database errors, with particular attention to WFS GetFeature requests using finite-limit/count parameters.
  • Revoke or restrict the pg_execute_server_program role attribute and superuser status from the database account GeoServer's PostGIS datastore connects with.

Workarounds

  • Where immediate upgrade is not possible, disable or unpublish any layers/filters that expose jsonArrayContains to untrusted network input.
  • Note: the CVE-2023-25158 mitigation (enabling prepared statements / disabling encode functions, or setting JDBC preferQueryMode to extended) is explicitly confirmed ineffective against this regression, per the GHSA advisory.

Longer-term hardening

  • Enforce least-privilege database roles for all GeoServer JDBC datastores; never bind GeoServer to a PostgreSQL superuser account.
  • Track GeoServer/GeoTools security advisories closely given the platform's recurring OGC Filter SQL injection history (CVE-2023-25158 and this regression).
  • Deploy a WAF or reverse proxy capable of inspecting OGC/WFS/WMS query parameters (CQL_FILTER, filter XML) for SQL injection patterns.

Weaknesses (CWE) in Unpatched GeoServer Zero-Day SQL Injection in

CWE-89

Timeline of Unpatched GeoServer Zero-Day SQL Injection in

  • GeoTools patches CVE-2023-25158 (GHSA-99c3-qc2q-p94m, CVSS 9.8), a prior critical OGC Filter SQL injection in JDBCDataStore implementations (PropertyIsLike/strEndsWith); its 'enable prepared statements / disable encode functions' mitigation guidance is later shown ineffective against the jsonArrayContains regression.
  • CVE-2024-36401, a GeoTools unsafe XPath-evaluation RCE (CVSS 9.8), is added to the CISA Known Exploited Vulnerabilities catalog after real-world exploitation of internet-facing GeoServer instances for web shells, DDoS botnets, and cryptomining, including a U.S. federal agency compromise within two weeks of disclosure.
  • WatchTowr begins observing hundreds of exploitation/probing attempts against internet-facing GeoServer instances, originating from a small number of source IP addresses, within hours of public disclosure.
  • Researcher @q1uf3ng publicly discloses the GeoServer jsonArrayContains SQL injection on X at 10:46 UTC without coordinated disclosure to the GeoServer project, leaving the flaw unpatched with no CVE assigned.
  • SecurityWeek, The Hacker News, Security Affairs, Field Effect, and CSO Online publish independent coverage; WatchTowr's Jake Knott characterizes the activity as reconnaissance-stage probing that triggers database errors without confirmed follow-on payload delivery, and warns it will likely escalate.
  • Public proof-of-concept exploit code (GeoServer-jsonArrayContains-PG-RCE on GitHub, and an accompanying gist) is released demonstrating the full SQLi-to-RCE chain via WFS 2.0 finite-limit/count requests and PostgreSQL's COPY TO PROGRAM.
  • The GeoServer Project Steering Committee releases GeoServer 3.0.1, 2.28.5, and 2.27.6 (with Docker images and Windows installers) fixing the flaw, crediting Andrea Aime (GeoSolutions) and Jody Garnett (GeoCat) for the expedited response.
  • GitHub Security Advisory GHSA-mqjf-5f49-2fjh is formally published against org.geotools:gt-jdbc-postgis (CVSS 9.8, CWE-89), confirming patched releases 35.1/34.5/33.6, referencing OSGeo JIRA ticket GEOT-7958, and crediting reporters qquang, mrlihd, PhilipPhil, and Quikko — distinct from public discloser @q1uf3ng.

Sources cited for Unpatched GeoServer Zero-Day SQL Injection in

Detection coverage for TL-2026-2035

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2035 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats