Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation — Threadlinqs Intelligence
As of 2026-08-16, Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitation is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-2037 · Severity: CRITICAL · CVSS: 9.8 · Status: ACTIVE · Category: VULNERABILITY
An uncoordinated public disclosure on August 12, 2026 by researcher @q1uf3ng exposed a critical unauthenticated SQL injection in GeoTools' jsonArrayContains OGC Filter function against PostGIS
On August 12, 2026 at 10:46 UTC, researcher @q1uf3ng publicly disclosed on X — without following coordinated vulnerability disclosure procedures — a critical SQL injection vulnerability in GeoTools' `jsonArrayContains(<column>, <pointer>, <value>)` OGC Filter function. The function writes the caller-supplied `<value>` argument directly into generated SQL without escaping when queried against a PostGIS DataStore (PostGIS 12+) with a String or JSON field, allowing an unauthenticated attacker to inject arbitrary SQL. Under configurations where the backing database account holds administrator privileges, the injection can be leveraged to execute operating-system commands, escalating a data-layer SQL injection into full remote code execution. The GeoTools advisory states "no mitigation is available at this time" and that the previously recommended workaround (prepared statements + disabled PostGIS encode functions) does not stop this instance. Some reporting additionally flags certain H2 DataStore configurations as a further RCE path, though the exact conditions required have not been publicly documented as of August 13, 2026.
The flaw is a regression of the jsonArrayContains SQL-injection class first disclosed on February 20, 2023 as CVE-2023-25157 (GeoServer) / CVE-2023-25158 (GeoTools, GHSA-99c3-qc2q-p94m).
watchTowr began observing exploitation activity within hours of the public disclosure, documenting hundreds of attempts originating from a small pool of source IP addresses. Principal researcher Jake Knott characterized the observed activity as reconnaissance — attackers triggering SQL errors to fingerprint vulnerable, internet-facing GeoServer instances rather than delivering follow-on payloads — but cautioned this is unlikely to remain the case for long given GeoServer's "track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog."
That track record includes CVE-2024-36401 (CVSS 9.8, an unrelated GeoTools property-name/XPath eval-injection RCE via Apache Commons JXPath), which CISA added to its KEV catalog on July 15, 2024. Per CISA advisory AA25-266A (published September 23, 2025), threat actors exploited CVE-2024-36401 to gain unauthenticated RCE on a U.S. federal civilian agency's internet-facing GeoServer on July 11, 2024; the intrusion went undetected for roughly three weeks because the web server lacked EDR coverage. During that window the actors used PowerShell and `xp_cmdshell` for execution, pivoted from the web server to an internal SQL server, breached a second internet-facing GeoServer via the same CVE on July 24, 2024, and moved laterally to two additional servers. Persistence was established via China Chopper/PHP web shells, Windows local-account creation (`net user`), and Linux cron jobs; the RingQ evasion loader was used to hinder AV/EDR detection; and Stowaway, a multi-level reverse-proxy utility, tunneled command-and-control traffic over HTTP on TCP/4441. Separately, FortiGuard Labs and other researchers documented mass, opportunistic exploitation of CVE-2024-36401 since mid-2024 — reportedly affecting roughly 7,100 internet-facing GeoServer instances worldwide — to deploy XMRig cryptocurrency miners, the Mirai-variant "JenX" and Condi DDoS botnet malware, the SideWalk backdoor, and residential-proxy monetization tooling.
GeoServer/GeoTools maintainers (Andrea Aime of GeoSolutions and Jody Garnett of GeoCat) shipped fixed releases — GeoServer 3.0.1, 2.28.5, and 2.27.6, and GeoTools gt-jdbc-postgis 35.1, 34.5, and 33.6 — on August 14-15, 2026, publishing the fix as GitHub Security Advisory GHSA-mqjf-5f49-2fjh (CWE-89, CVSS 3.1 9.8: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), tracked via GeoTools JIRA ticket GEOT-7958 / PR #5829. No CVE identifier had been assigned as of the advisory's publication. GeoServer's user base spans government, defense, science, education, engineering, and technology sectors, consistent with its docume
Target sectors: government administration, defense, science, education, engineering, technology
Target regions: Global
Timeline
- CVE-2023-25157 (GeoServer) / CVE-2023-25158 (GeoTools, GHSA-99c3-qc2q-p94m) disclosed: the original OGC Filter/jsonArrayContains SQL injection class, of which this 2026 flaw is a regression.
- CVE-2024-36401, an unrelated GeoTools property-name/XPath eval-injection RCE, disclosed — later exploited in the wild and added to CISA KEV.
- Threat actors exploit CVE-2024-36401 for initial access against a U.S. federal agency's public-facing GeoServer instance, per CISA AA25-266a.
- CISA adds CVE-2024-36401 to the Known Exploited Vulnerabilities catalog, requiring federal remediation by August 5, 2024.
- The same actors breach a second internet-facing GeoServer at the federal agency via CVE-2024-36401 and move laterally to two additional internal servers, per CISA AA25-266A.
- CISA publishes advisory AA25-266A detailing the federal-agency GeoServer breach TTPs (PowerShell, Stowaway proxy C2, China Chopper web shells) and lessons learned (delayed patching, untested IR plans, missing EDR).
- Researcher @q1uf3ng publicly discloses the jsonArrayContains SQL injection on X at 10:46 UTC without coordinated vulnerability disclosure.
- watchTowr begins observing exploitation attempts within hours of disclosure, recording hundreds of scanning/probing attempts from a small pool of source IP addresses.
- The Hacker News, SecurityWeek, CSO Online, Security Affairs, and Field Effect publish coverage of the unpatched zero-day and active exploitation attempts.
- GeoServer 3.0.1, 2.28.5, and 2.27.6 (bundling patched GeoTools gt-jdbc-postgis) are released.
- GitHub Security Advisory GHSA-mqjf-5f49-2fjh formally published for GeoTools gt-jdbc-postgis; no CVE identifier assigned as of publication.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, T1595.002, T1592.002, T1588.005, T1584.005, T1190, T1059, T1059.001, T1505.003, T1136.001, T1053.003