Skip to main content
QUIETLYTIC
Vulnerability

GeoTools SQL Injection (CVE-2026-76904)

CVE-2026-76904 is a CVSS 9.8 SQL injection flaw in GeoTools PostGIS integration via jsonArrayContains, reported exploited by VulnCheck KEV.

CVE-2026-76904
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
GeoTools, GeoTools (30.5 through before 33.6/34.5/35.1)

CVE-2026-76904 carries a CVSS 3.1 base score of 9.8 against GeoTools, an open-source Java library for processing geospatial data. NVD classifies it as CWE-89 (SQL Injection) and states the flaw affects versions starting at 30.5, before patched releases 33.6, 34.5, and 35.1. VulnCheck’s KEV feed reports the CVE as exploited, dated August 21, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-76904 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description names the exact vulnerable function: jsonArrayContains, used when executing OGC (Open Geospatial Consortium) filter queries against a PostGIS-backed data store. The function takes a column, a pointer, and a value, and NVD states that the value argument is written directly into the generated SQL query without escaping. Two preconditions apply, per NVD: the underlying database must be PostGIS 12 or later, and the targeted column must be a String or JSON-typed field. GeoTools’ own GitHub security advisory, cited from NVD’s reference list, confirms the same root cause.

NVD states no workaround is available. Its own interim mitigation guidance — configuring the PostGIS connection pool with limited rights — reduces the blast radius of a successful injection rather than closing the vulnerability itself.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-89 classification, the vulnerable function, and the two preconditions (PostGIS 12+, String/JSON column type) all trace to NVD alone, corroborated by GeoTools’ own linked GitHub security advisory for the technical root cause specifically. The exploitation report traces to VulnCheck KEV alone.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.01791, a 77.3rd percentile score as of our ingestion.

No field is in conflict between our two sources. NVD’s own description text names the fixed versions as “33.6, 34.5, and 33.6” — we treat the third figure as a likely duplication in NVD’s own text, since GeoTools’ GitHub release tags cited in the same NVD record list 33.6, 34.5, and 35.1 as the three patched releases; we report the GitHub-sourced 35.1 figure rather than repeat what NVD’s own description appears to have mistyped.

Why this matters

GeoTools underpins geospatial functionality inside a range of downstream Java-based mapping and GIS applications, meaning the practical exposure surface extends beyond direct GeoTools users to anything embedding it, and an operator may not immediately realize a dependency is affected without checking a full dependency tree rather than just top-level application versions. Because no workaround exists and the interim guidance (restricting database connection-pool rights) only limits damage rather than preventing exploitation, upgrading to a patched release is the only complete remediation NVD describes.

The specific precondition — PostGIS 12 or later with a String or JSON column — means exposure depends on how a given deployment’s data store and schema are configured, not simply on which GeoTools version is installed; operators should check both the GeoTools version and the PostGIS/column configuration described here.

Frequently Asked Questions

What is CVE-2026-76904? A CVSS 9.8 SQL injection vulnerability (CWE-89) in GeoTools’ PostGIS integration, in the jsonArrayContains function, affecting versions from 30.5 before patched releases 33.6, 34.5, and 35.1.

Is CVE-2026-76904 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 21, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Is there a workaround if I can’t upgrade immediately? NVD states no workaround is available. Configuring the PostGIS connection pool with limited rights can reduce the impact of a successful injection but does not prevent exploitation.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which versions fix this? 33.6, 34.5, and 35.1, per GeoTools’ own GitHub release tags cited in NVD’s record.


Severity, vector, weakness classification, vulnerable function, and preconditions sourced from the National Vulnerability Database record for CVE-2026-76904, corroborated by GeoTools’ own GitHub security advisory. Fixed versions confirmed via GeoTools’ 33.6, 34.5, and 35.1 release tags. Exploitation status and the August 21, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools