{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/osgeo/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76904"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GeoTools"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","application-security"],"_cs_type":"advisory","_cs_vendors":["OSGeo"],"content_html":"\u003cp\u003eGeoTools, a popular Java library for geospatial data, contains a critical SQL injection vulnerability (CVE-2026-76904) within its PostGIS DataStore implementation. The flaw resides in the jsonArrayContains filter function, which fails to properly sanitize the input value parameter when generating SQL queries for databases running PostGIS 12 or later. By providing malicious input to this function, an unauthenticated attacker can inject arbitrary SQL commands into the backend database. This vulnerability affects multiple versions of the gt-jdbc-postgis package, specifically versions 35.0, 34.0 through 34.4, and 30.5 through 33.5. Impacted organizations are advised to upgrade to the patched versions (35.1, 33.5, or 34.4) immediately. If upgrading is not immediately feasible, the attack surface can be limited by ensuring the database connection pool used by the GeoTools application is configured with the principle of least privilege, specifically restricting write and administrative permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to execute arbitrary SQL expressions against the underlying database. This potentially results in complete data exfiltration, unauthorized modification of geospatial datasets, and database-level compromise. The vulnerability is highly severe due to its unauthenticated nature and the direct access to database operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the gt-jdbc-postgis library to versions 35.1, 33.5, or 34.4 immediately to resolve CVE-2026-76904.\u003c/li\u003e\n\u003cli\u003eReview database connection pool configurations and restrict the service account privileges assigned to GeoTools to the minimum required subset of data (SELECT only where possible).\u003c/li\u003e\n\u003cli\u003eEnable detailed logging for database queries in the application layer to monitor for anomalous SQL syntax or unexpected execution patterns that may indicate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T01:16:54Z","date_published":"2026-08-22T01:16:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-geotools-sql-injection/","summary":"A critical unauthenticated SQL injection vulnerability (CVE-2026-76904) in the GeoTools library allows remote attackers to execute arbitrary SQL via the jsonArrayContains filter function.","title":"Unauthenticated SQL Injection in GeoTools PostGIS DataStore","url":"https://feed.craftedsignal.io/briefs/2026-08-geotools-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - OSGeo","version":"https://jsonfeed.org/version/1.1"}